CVE-2026-98318
In the Linux kernel, the following vulnerability has been resolved:
smb: client: validate absolute native symlink targets before NT fixups
With symlinkroot unset, an absolute target is copied without conversion to an NT drive path. Later code still assumes an NT prefix is present when modifying the target and calculating the print name length.
For "/ab", this causes two failures: sym[5] and path[5] are written past their allocations, and plen -= 2 * poff subtracts an assumed 8-byte prefix from a 6-byte UTF-16 target, wrapping u16 plen to 65534. That underflow causes another overflow: memcpy() copies 65534 bytes into a 24-byte buffer. A user with write access to a mounted share can trigger these bugs with default settings.
Leer descripción completaMostrar menos
Validate the NT drive prefix, including an ASCII drive letter, before accessing fixed offsets or subtracting the prefix length.
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.16%
- Percentil entre todas las CVEs puntuadas: 5
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-98318",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "3363da82e02f1bddc54faa92ea430c6532e2cd2e",
"lessThan": "6913ff607c2bc8694193e1fcc40bf16d75f35f16",
"versionType": "git"
},
{
"status": "affected",
"version": "3363da82e02f1bddc54faa92ea430c6532e2cd2e",
"lessThan": "23c240d9509e15f72e4112fc95f0160ab32ec430",
"versionType": "git"
},
{
"status": "affected",
"version": "b6ea7b6c6be65149ab6b8e37a9dd1671f76add1b",
"versionType": "git"
},
{
"status": "affected",
"version": "6.15.6",
"lessThan": "6.16",
"versionType": "semver"
}
],
"programFiles": [
"fs/smb/client/reparse.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6.16"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "6.16",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "7.2.8",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc4",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"fs/smb/client/reparse.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-10-06T09:18:23.670",
"references": [
{
"url": "https://git.kernel.org/stable/c/23c240d9509e15f72e4112fc95f0160ab32ec430",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/6913ff607c2bc8694193e1fcc40bf16d75f35f16",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: validate absolute native symlink targets before NT fixups\n\nWith symlinkroot unset, an absolute target is copied without conversion\nto an NT drive path. Later code still assumes an NT prefix is present\nwhen modifying the target and calculating the print name length.\n\nFor \"/ab\", this causes two failures: sym[5] and path[5] are written\npast their allocations, and plen -= 2 * poff subtracts an assumed\n8-byte prefix from a 6-byte UTF-16 target, wrapping u16 plen to 65534.\nThat underflow causes another overflow: memcpy() copies 65534 bytes\ninto a 24-byte buffer. A user with write access to a mounted share\ncan trigger these bugs with default settings.\n\nValidate the NT drive prefix, including an ASCII drive letter, before\naccessing fixed offsets or subtracting the prefix length."
}
],
"lastModified": "2026-10-06T09:18:23.670",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}