← All Advisories

CVE-2026-98169

Last refreshed2026-10-09

Status: UPDATED  |  Advisory ID: CVE-2026-98169

Key Details

CVECVE-2026-98169
CVSS Score / Version7.1 (High) / CVSS v3.1
Updated2026-10-07
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is required; scope is unchanged; confidentiality impact is low; integrity impact is none; availability impact is high.
Affected productsLinux Kernel

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux Kernel
SubsystemsOT Supporting Infrastructure
SectorsAll Sectors

What to Know

In the Linux kernel, the following vulnerability has been resolved:

smb: client: fix potential OOB read in smb3_enum_snapshots()

If snapshot_array_size is smaller than GMT_TOKEN_SIZE,

smb3_enum_snapshots() sets ret_data_len to

sizeof(struct smb_snapshot_array) without verifying the actual length

of the server's reply.

Because SMB2_ioctl() places no lower bound on the server-supplied

OutputCount and allocates retbuf to exactly that length, a short reply

results in ret_data_len exceeding the size of retbuf. The subsequent

copy_to_user() then reads past the end of retbuf, leaking adjacent slab

memory to userspace. The subsequent clamp check is ineffective as it

only reduces ret_data_len.

Fix this by rejecting replies shorter than

sizeof(struct smb_snapshot_array) with -EIO. Note that the bound is set

to the 12-byte struct size rather than the 16-byte

MIN_SNAPSHOT_ARRAY_SIZE defined in MS-SMB2 3.3.5.15.1, because 12 bytes

is exactly what copy_to_user() attempts to read. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-98169
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-98169