« Volver al listado

CVE-2026-98169

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

smb: client: fix potential OOB read in smb3_enum_snapshots()

If snapshot_array_size is smaller than GMT_TOKEN_SIZE, smb3_enum_snapshots() sets ret_data_len to sizeof(struct smb_snapshot_array) without verifying the actual length of the server's reply.

Because SMB2_ioctl() places no lower bound on the server-supplied OutputCount and allocates retbuf to exactly that length, a short reply results in ret_data_len exceeding the size of retbuf. The subsequent copy_to_user() then reads past the end of retbuf, leaking adjacent slab memory to userspace. The subsequent clamp check is ineffective as it only reduces ret_data_len.

Leer descripción completaMostrar menos

Fix this by rejecting replies shorter than sizeof(struct smb_snapshot_array) with -EIO. Note that the bound is set to the 12-byte struct size rather than the 16-byte MIN_SNAPSHOT_ARRAY_SIZE defined in MS-SMB2 3.3.5.15.1, because 12 bytes is exactly what copy_to_user() attempts to read.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-98169",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "e02789a53d71334b067ad72eee5d4e88a0158083",
              "lessThan": "15a221c734b9d044ab769e7e3606b2cab96fb65a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "e02789a53d71334b067ad72eee5d4e88a0158083",
              "lessThan": "74995ee8305a7c4d76ee70d6acd996a75eda3c03",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "e02789a53d71334b067ad72eee5d4e88a0158083",
              "lessThan": "210f0f1f67817e7d2348b86b5115a9b85ef5c98b",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "e02789a53d71334b067ad72eee5d4e88a0158083",
              "lessThan": "1cdf0d304d820fb13bf0faf532c3459600f9ea43",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "e02789a53d71334b067ad72eee5d4e88a0158083",
              "lessThan": "dbe452a905dfe2804647530a9ff3d7e3826ed04d",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "e02789a53d71334b067ad72eee5d4e88a0158083",
              "lessThan": "4775c3b7a597907e0b97556c7986fda238a377ae",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "a94703ff8e3647f8a9a3a92a468450299a7b77e9",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "82a856f527334ffd69aae26e7dd9e03b19c4a520",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "25b981bfe192fd208ba04c81f4aa30ffb5141660",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "4.9.125",
              "lessThan": "4.10",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "4.14.68",
              "lessThan": "4.15",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "4.18.6",
              "lessThan": "4.19",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "fs/smb/client/smb2ops.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4.19"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "4.19",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.1.189",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.158",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.112",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.54",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.8",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc4",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "fs/smb/client/smb2ops.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-10-06T09:17:58.480",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/15a221c734b9d044ab769e7e3606b2cab96fb65a",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/1cdf0d304d820fb13bf0faf532c3459600f9ea43",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/210f0f1f67817e7d2348b86b5115a9b85ef5c98b",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/4775c3b7a597907e0b97556c7986fda238a377ae",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/74995ee8305a7c4d76ee70d6acd996a75eda3c03",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/dbe452a905dfe2804647530a9ff3d7e3826ed04d",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: fix potential OOB read in smb3_enum_snapshots()\n\nIf snapshot_array_size is smaller than GMT_TOKEN_SIZE,\nsmb3_enum_snapshots() sets ret_data_len to\nsizeof(struct smb_snapshot_array) without verifying the actual length\nof the server's reply.\n\nBecause SMB2_ioctl() places no lower bound on the server-supplied\nOutputCount and allocates retbuf to exactly that length, a short reply\nresults in ret_data_len exceeding the size of retbuf. The subsequent\ncopy_to_user() then reads past the end of retbuf, leaking adjacent slab\nmemory to userspace.  The subsequent clamp check is ineffective as it\nonly reduces ret_data_len.\n\nFix this by rejecting replies shorter than\nsizeof(struct smb_snapshot_array) with -EIO. Note that the bound is set\nto the 12-byte struct size rather than the 16-byte\nMIN_SNAPSHOT_ARRAY_SIZE defined in MS-SMB2 3.3.5.15.1, because 12 bytes\nis exactly what copy_to_user() attempts to read."
    }
  ],
  "lastModified": "2026-10-06T09:17:58.480",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}