« Volver al listado

CVE-2026-98171

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

smb: client: fix next_buffer UAF and NextCommand bounds in compound PDUs

Fix several related bounds checking and pointer lifecycle issues in receive_encrypted_standard()'s handling of compound encrypted frames:

Detalles técnicos trazas, registros y código del informe original
- Clear next_buffer after assigning it to server->bigbuf. A stale
  next_buffer pointer can lead to a use-after-free on subsequent
  error paths.
- Update pdu_length to the decrypted plaintext size (buf_size). Using
  the pre-decryption length allows NextCommand to point into stale
  ciphertext residue.
- Reject next_cmd values smaller than MID_HEADER_SIZE(server).
- Fix an integer overflow in the upper bound check by verifying
  pdu_length - next_cmd < MID_HEADER_SIZE(server), ensuring the
  trailing slice is large enough for a header.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-98171",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "b24df3e30cbf48255db866720fb71f14bf9d2f39",
              "lessThan": "72eaef1f37a3b6bec11c342736834dc3707be3e4",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "b24df3e30cbf48255db866720fb71f14bf9d2f39",
              "lessThan": "491e33144dee872cffda207f6fcb09260728f803",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "b24df3e30cbf48255db866720fb71f14bf9d2f39",
              "lessThan": "8749946579708ea0d339034bb7f423a67dbe89cf",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "b24df3e30cbf48255db866720fb71f14bf9d2f39",
              "lessThan": "96c436e4b010711452b2872558938f4ef276492a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "b24df3e30cbf48255db866720fb71f14bf9d2f39",
              "lessThan": "858d5ac22cb889266993e7670f9f0c4f4aeedd78",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "b24df3e30cbf48255db866720fb71f14bf9d2f39",
              "lessThan": "05762c5bc1cfdcac36747994fde2c04387a457f1",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "fs/smb/client/smb2ops.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4.19"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "4.19",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.1.189",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.158",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.112",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.54",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.8",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc4",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "fs/smb/client/smb2ops.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-10-06T09:17:58.773",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/05762c5bc1cfdcac36747994fde2c04387a457f1",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/491e33144dee872cffda207f6fcb09260728f803",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/72eaef1f37a3b6bec11c342736834dc3707be3e4",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/858d5ac22cb889266993e7670f9f0c4f4aeedd78",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/8749946579708ea0d339034bb7f423a67dbe89cf",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/96c436e4b010711452b2872558938f4ef276492a",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: fix next_buffer UAF and NextCommand bounds in compound PDUs\n\nFix several related bounds checking and pointer lifecycle issues in\nreceive_encrypted_standard()'s handling of compound encrypted frames:\n\n- Clear next_buffer after assigning it to server->bigbuf. A stale\n  next_buffer pointer can lead to a use-after-free on subsequent\n  error paths.\n- Update pdu_length to the decrypted plaintext size (buf_size). Using\n  the pre-decryption length allows NextCommand to point into stale\n  ciphertext residue.\n- Reject next_cmd values smaller than MID_HEADER_SIZE(server).\n- Fix an integer overflow in the upper bound check by verifying\n  pdu_length - next_cmd < MID_HEADER_SIZE(server), ensuring the\n  trailing slice is large enough for a header."
    }
  ],
  "lastModified": "2026-10-06T09:17:58.773",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}