CVE-2026-98169
Received Received - Intake

Out-of-Bounds Read in Linux Kernel SMB Client

Vulnerability report for CVE-2026-98169, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix potential OOB read in smb3_enum_snapshots() If snapshot_array_size is smaller than GMT_TOKEN_SIZE, smb3_enum_snapshots() sets ret_data_len to sizeof(struct smb_snapshot_array) without verifying the actual length of the server's reply. Because SMB2_ioctl() places no lower bound on the server-supplied OutputCount and allocates retbuf to exactly that length, a short reply results in ret_data_len exceeding the size of retbuf. The subsequent copy_to_user() then reads past the end of retbuf, leaking adjacent slab memory to userspace. The subsequent clamp check is ineffective as it only reduces ret_data_len. Fix this by rejecting replies shorter than sizeof(struct smb_snapshot_array) with -EIO. Note that the bound is set to the 12-byte struct size rather than the 16-byte MIN_SNAPSHOT_ARRAY_SIZE defined in MS-SMB2 3.3.5.15.1, because 12 bytes is exactly what copy_to_user() attempts to read.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 13 associated CPEs
Vendor Product Version / Range
Linux Linux e02789a53d71334b067ad72eee5d4e88a0158083
Linux Linux e02789a53d71334b067ad72eee5d4e88a0158083
Linux Linux e02789a53d71334b067ad72eee5d4e88a0158083
Linux Linux e02789a53d71334b067ad72eee5d4e88a0158083
Linux Linux e02789a53d71334b067ad72eee5d4e88a0158083
Linux Linux e02789a53d71334b067ad72eee5d4e88a0158083
Linux Linux a94703ff8e3647f8a9a3a92a468450299a7b77e9
Linux Linux 82a856f527334ffd69aae26e7dd9e03b19c4a520
Linux Linux 25b981bfe192fd208ba04c81f4aa30ffb5141660
Linux Linux 4.9.125
Linux Linux 4.14.68
Linux Linux 4.18.6
Linux Linux 4.19

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a vulnerability in the Linux kernel's SMB client implementation. It involves a potential out-of-bounds (OOB) read in the smb3_enum_snapshots() function. When processing snapshot data from a server, the function fails to properly validate the size of the received data. If the server sends a reply smaller than expected, the function may attempt to read beyond the allocated buffer, leaking adjacent memory to userspace.

Impact Analysis

This vulnerability could allow an attacker to read sensitive memory from the kernel, potentially exposing confidential data. It may also be used to crash the system or escalate privileges. Systems using vulnerable SMB client versions are at risk if they connect to malicious SMB servers.

Mitigation Strategies

Apply the Linux kernel patch that fixes the OOB read in smb3_enum_snapshots(). Update to a version containing the fix for CVE-2026-98169. Monitor vendor advisories for kernel updates.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-98169. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart