๐Ÿ” CVE Alert

CVE-2026-98167

UNKNOWN 0.0

smb: client: fix server->total_read for compound encrypted PDUs

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix server->total_read for compound encrypted PDUs In receive_encrypted_standard(), server->total_read is left at the full decrypted frame size when walking sub-PDUs of a compound encrypted frame. As a result, cifs_handle_standard() passes this full size to smb2_check_message(), causing the PDU length guards to incorrectly validate the entire compound frame instead of the current sub-PDU. This allows truncated non-last sub-PDUs to bypass length validation, leading to out-of-bounds reads in smb2_get_data_area_len(). Fix this by setting server->total_read to the true length of the current sub-PDU: next_cmd for non-last sub-PDUs, and the remaining pdu_length for the last one.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Oct 6, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
b24df3e30cbf48255db866720fb71f14bf9d2f39 < 8703539d22fdbc13dd2db090ee199c3a427b8ea0 b24df3e30cbf48255db866720fb71f14bf9d2f39 < e78fc1d240b27349b45a0f1c3e3c2c401d7e230d b24df3e30cbf48255db866720fb71f14bf9d2f39 < a46eb242e9eef3a3897d166748b23303c516e870 b24df3e30cbf48255db866720fb71f14bf9d2f39 < ebb8a075fdc7af3d196a4f158a0e18dbc394c0e3 b24df3e30cbf48255db866720fb71f14bf9d2f39 < 282b72f9a7ef31296c48366db4128882999cc048 b24df3e30cbf48255db866720fb71f14bf9d2f39 < f73726b83e4756fdaa099e1bc1143293bd57ad79
Linux / Linux
4.19

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/8703539d22fdbc13dd2db090ee199c3a427b8ea0 git.kernel.org: https://git.kernel.org/stable/c/e78fc1d240b27349b45a0f1c3e3c2c401d7e230d git.kernel.org: https://git.kernel.org/stable/c/a46eb242e9eef3a3897d166748b23303c516e870 git.kernel.org: https://git.kernel.org/stable/c/ebb8a075fdc7af3d196a4f158a0e18dbc394c0e3 git.kernel.org: https://git.kernel.org/stable/c/282b72f9a7ef31296c48366db4128882999cc048 git.kernel.org: https://git.kernel.org/stable/c/f73726b83e4756fdaa099e1bc1143293bd57ad79