CVE-2026-98167
Received
Received - Intake
Linux Kernel SMB Client Buffer Overflow Fix
Vulnerability report for CVE-2026-98167, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-10-06
Last updated on: 2026-10-06
Assigner: kernel.org
Description
Description
In the Linux kernel, the following vulnerability has been resolved:
smb: client: fix server->total_read for compound encrypted PDUs
In receive_encrypted_standard(), server->total_read is left at the
full decrypted frame size when walking sub-PDUs of a compound encrypted
frame. As a result, cifs_handle_standard() passes this full size
to smb2_check_message(), causing the PDU length guards to incorrectly
validate the entire compound frame instead of the current sub-PDU.
This allows truncated non-last sub-PDUs to bypass length validation,
leading to out-of-bounds reads in smb2_get_data_area_len().
Fix this by setting server->total_read to the true length of the
current sub-PDU: next_cmd for non-last sub-PDUs, and the remaining
pdu_length for the last one.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| Linux | Linux | b24df3e30cbf48255db866720fb71f14bf9d2f39 |
| Linux | Linux | b24df3e30cbf48255db866720fb71f14bf9d2f39 |
| Linux | Linux | b24df3e30cbf48255db866720fb71f14bf9d2f39 |
| Linux | Linux | b24df3e30cbf48255db866720fb71f14bf9d2f39 |
| Linux | Linux | b24df3e30cbf48255db866720fb71f14bf9d2f39 |
| Linux | Linux | b24df3e30cbf48255db866720fb71f14bf9d2f39 |
| Linux | Linux | 4.19 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |