CVE-2026-98171
Received Received - Intake

Use-After-Free in Linux Kernel SMB Client

Vulnerability report for CVE-2026-98171, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix next_buffer UAF and NextCommand bounds in compound PDUs Fix several related bounds checking and pointer lifecycle issues in receive_encrypted_standard()'s handling of compound encrypted frames: - Clear next_buffer after assigning it to server->bigbuf. A stale next_buffer pointer can lead to a use-after-free on subsequent error paths. - Update pdu_length to the decrypted plaintext size (buf_size). Using the pre-decryption length allows NextCommand to point into stale ciphertext residue. - Reject next_cmd values smaller than MID_HEADER_SIZE(server). - Fix an integer overflow in the upper bound check by verifying pdu_length - next_cmd < MID_HEADER_SIZE(server), ensuring the trailing slice is large enough for a header.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 7 associated CPEs
Vendor Product Version / Range
Linux Linux b24df3e30cbf48255db866720fb71f14bf9d2f39
Linux Linux b24df3e30cbf48255db866720fb71f14bf9d2f39
Linux Linux b24df3e30cbf48255db866720fb71f14bf9d2f39
Linux Linux b24df3e30cbf48255db866720fb71f14bf9d2f39
Linux Linux b24df3e30cbf48255db866720fb71f14bf9d2f39
Linux Linux b24df3e30cbf48255db866720fb71f14bf9d2f39
Linux Linux 4.19

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel involves improper handling of compound encrypted frames in the SMB client. It includes use-after-free (UAF) and bounds checking issues in the receive_encrypted_standard function. Specifically, it allows stale pointers to persist, leading to memory corruption, and incorrect length calculations that could expose plaintext data or cause crashes.

Detection Guidance

This vulnerability is specific to the Linux kernel's SMB client implementation and requires kernel-level detection. There are no standard network commands to detect it directly. Monitoring kernel logs for SMB-related errors or crashes after receiving encrypted compound PDUs may indicate exploitation attempts. Check for kernel oops or warnings related to smb or receive_encrypted_standard.

Impact Analysis

If exploited, this vulnerability could allow an attacker to crash the system, execute arbitrary code, or leak sensitive information by manipulating SMB client operations. It primarily affects systems using the Linux kernel with SMB client functionality enabled.

Mitigation Strategies

Apply the latest Linux kernel security updates immediately. Disable SMB encryption if not required or restrict SMB access to trusted networks. Monitor for unusual SMB traffic patterns or crashes. Consider using kernel hardening features like KASLR or disabling SMBv3 encryption temporarily until patched.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-98171. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart