๐Ÿ” CVE Alert

CVE-2026-98169

UNKNOWN 0.0

smb: client: fix potential OOB read in smb3_enum_snapshots()

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix potential OOB read in smb3_enum_snapshots() If snapshot_array_size is smaller than GMT_TOKEN_SIZE, smb3_enum_snapshots() sets ret_data_len to sizeof(struct smb_snapshot_array) without verifying the actual length of the server's reply. Because SMB2_ioctl() places no lower bound on the server-supplied OutputCount and allocates retbuf to exactly that length, a short reply results in ret_data_len exceeding the size of retbuf. The subsequent copy_to_user() then reads past the end of retbuf, leaking adjacent slab memory to userspace. The subsequent clamp check is ineffective as it only reduces ret_data_len. Fix this by rejecting replies shorter than sizeof(struct smb_snapshot_array) with -EIO. Note that the bound is set to the 12-byte struct size rather than the 16-byte MIN_SNAPSHOT_ARRAY_SIZE defined in MS-SMB2 3.3.5.15.1, because 12 bytes is exactly what copy_to_user() attempts to read.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Oct 6, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
e02789a53d71334b067ad72eee5d4e88a0158083 < 15a221c734b9d044ab769e7e3606b2cab96fb65a e02789a53d71334b067ad72eee5d4e88a0158083 < 74995ee8305a7c4d76ee70d6acd996a75eda3c03 e02789a53d71334b067ad72eee5d4e88a0158083 < 210f0f1f67817e7d2348b86b5115a9b85ef5c98b e02789a53d71334b067ad72eee5d4e88a0158083 < 1cdf0d304d820fb13bf0faf532c3459600f9ea43 e02789a53d71334b067ad72eee5d4e88a0158083 < dbe452a905dfe2804647530a9ff3d7e3826ed04d e02789a53d71334b067ad72eee5d4e88a0158083 < 4775c3b7a597907e0b97556c7986fda238a377ae a94703ff8e3647f8a9a3a92a468450299a7b77e9 82a856f527334ffd69aae26e7dd9e03b19c4a520 25b981bfe192fd208ba04c81f4aa30ffb5141660 4.9.125 < 4.10 4.14.68 < 4.15 4.18.6 < 4.19
Linux / Linux
4.19

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/15a221c734b9d044ab769e7e3606b2cab96fb65a git.kernel.org: https://git.kernel.org/stable/c/74995ee8305a7c4d76ee70d6acd996a75eda3c03 git.kernel.org: https://git.kernel.org/stable/c/210f0f1f67817e7d2348b86b5115a9b85ef5c98b git.kernel.org: https://git.kernel.org/stable/c/1cdf0d304d820fb13bf0faf532c3459600f9ea43 git.kernel.org: https://git.kernel.org/stable/c/dbe452a905dfe2804647530a9ff3d7e3826ed04d git.kernel.org: https://git.kernel.org/stable/c/4775c3b7a597907e0b97556c7986fda238a377ae