CVE-2026-98167
Received Received - Intake

Linux Kernel SMB Client Buffer Overflow Fix

Vulnerability report for CVE-2026-98167, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix server->total_read for compound encrypted PDUs In receive_encrypted_standard(), server->total_read is left at the full decrypted frame size when walking sub-PDUs of a compound encrypted frame. As a result, cifs_handle_standard() passes this full size to smb2_check_message(), causing the PDU length guards to incorrectly validate the entire compound frame instead of the current sub-PDU. This allows truncated non-last sub-PDUs to bypass length validation, leading to out-of-bounds reads in smb2_get_data_area_len(). Fix this by setting server->total_read to the true length of the current sub-PDU: next_cmd for non-last sub-PDUs, and the remaining pdu_length for the last one.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 7 associated CPEs
Vendor Product Version / Range
Linux Linux b24df3e30cbf48255db866720fb71f14bf9d2f39
Linux Linux b24df3e30cbf48255db866720fb71f14bf9d2f39
Linux Linux b24df3e30cbf48255db866720fb71f14bf9d2f39
Linux Linux b24df3e30cbf48255db866720fb71f14bf9d2f39
Linux Linux b24df3e30cbf48255db866720fb71f14bf9d2f39
Linux Linux b24df3e30cbf48255db866720fb71f14bf9d2f39
Linux Linux 4.19

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel involves a flaw in the SMB client's handling of encrypted compound PDUs. When processing encrypted compound frames, the server's total_read value is incorrectly set to the full decrypted frame size instead of the current sub-PDU size. This causes validation checks to fail, allowing truncated non-last sub-PDUs to bypass length checks, potentially leading to out-of-bounds memory reads.

Detection Guidance

This vulnerability affects the Linux kernel's SMB client implementation and may lead to out-of-bounds reads. Detection requires checking if your system is running a vulnerable kernel version. Use commands like 'uname -a' to check the kernel version and compare it against patched versions. Monitor logs for SMB-related errors or crashes that may indicate exploitation attempts.

Impact Analysis

This vulnerability could allow an attacker to trigger out-of-bounds memory reads by sending maliciously crafted SMB messages. This may lead to system crashes, data corruption, or potential privilege escalation if exploited successfully. Systems using the affected Linux kernel versions with SMB client functionality are at risk.

Mitigation Strategies

Immediately update your Linux kernel to the latest patched version provided by your distribution. If updating is not immediately possible, consider disabling SMB client functionality or restricting network access to SMB servers until the patch is applied. Monitor vendor advisories for kernel updates addressing this issue.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-98167. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart