« Volver al listado

CVE-2026-98168

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

smb: client: fix reparse buffer bounds in cifs_query_reparse_point()

In cifs_query_reparse_point(), the start >= end check before casting to struct reparse_data_buffer * only ensures the start pointer is within the response. It fails to verify that there is enough space remaining for the fixed 8-byte header of the structure.

If a server provides a DataOffset that leaves less than 8 bytes remaining, the check passes, but subsequent reads of ReparseTag and ReparseDataLength will occur out-of-bounds.

Fix this by ensuring the remaining space is at least the size of the reparse_data_buffer structure before accessing its fields.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-98168",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "48ca7139ab7f0bbed95ff7a901ea497017769657",
              "lessThan": "3d67f155fe5813cfb02a551a9a12d6ea06a902e9",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "56e84c64fc257a95728ee73165456b025c48d408",
              "lessThan": "d1152c96a3002e3df6b9a5b007cecaa7b19b4f79",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "56e84c64fc257a95728ee73165456b025c48d408",
              "lessThan": "8dc5db3a0e583ea8d31d0613cefd99e93e095c3c",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "56e84c64fc257a95728ee73165456b025c48d408",
              "lessThan": "5f0306e731e2f46e91419eae57eee3a241c055e0",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "848d78e3625f15de09d34a562dc49a98b78a62f3",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "c13b779d26b3702fba8f7d5fe757aba5bda85fd0",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "6.12.34",
              "lessThan": "6.12.112",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.6.94",
              "lessThan": "6.7",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.15.3",
              "lessThan": "6.16",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "fs/smb/client/cifssmb.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.16"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.16",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.12.112",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.54",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.8",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc4",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "fs/smb/client/cifssmb.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-10-06T09:17:58.333",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/3d67f155fe5813cfb02a551a9a12d6ea06a902e9",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/5f0306e731e2f46e91419eae57eee3a241c055e0",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/8dc5db3a0e583ea8d31d0613cefd99e93e095c3c",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/d1152c96a3002e3df6b9a5b007cecaa7b19b4f79",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: fix reparse buffer bounds in cifs_query_reparse_point()\n\nIn cifs_query_reparse_point(), the start >= end check before casting to\nstruct reparse_data_buffer * only ensures the start pointer is within the\nresponse. It fails to verify that there is enough space remaining for the\nfixed 8-byte header of the structure.\n\nIf a server provides a DataOffset that leaves less than 8 bytes remaining,\nthe check passes, but subsequent reads of ReparseTag and ReparseDataLength\nwill occur out-of-bounds.\n\nFix this by ensuring the remaining space is at least the size of the\nreparse_data_buffer structure before accessing its fields."
    }
  ],
  "lastModified": "2026-10-06T09:17:58.333",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}