-

CVE-2026-98168

smb: client: fix reparse buffer bounds in cifs_query_reparse_point()

In the Linux kernel, the following vulnerability has been resolved:

smb: client: fix reparse buffer bounds in cifs_query_reparse_point()

In cifs_query_reparse_point(), the start >= end check before casting to
struct reparse_data_buffer * only ensures the start pointer is within the
response. It fails to verify that there is enough space remaining for the
fixed 8-byte header of the structure.

If a server provides a DataOffset that leaves less than 8 bytes remaining,
the check passes, but subsequent reads of ReparseTag and ReparseDataLength
will occur out-of-bounds.

Fix this by ensuring the remaining space is at least the size of the
reparse_data_buffer structure before accessing its fields.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 48ca7139ab7f0bbed95ff7a901ea497017769657
Version < 3d67f155fe5813cfb02a551a9a12d6ea06a902e9
Status affected
Version 56e84c64fc257a95728ee73165456b025c48d408
Version < d1152c96a3002e3df6b9a5b007cecaa7b19b4f79
Status affected
Version 56e84c64fc257a95728ee73165456b025c48d408
Version < 8dc5db3a0e583ea8d31d0613cefd99e93e095c3c
Status affected
Version 56e84c64fc257a95728ee73165456b025c48d408
Version < 5f0306e731e2f46e91419eae57eee3a241c055e0
Status affected
Version 848d78e3625f15de09d34a562dc49a98b78a62f3
Status affected
Version c13b779d26b3702fba8f7d5fe757aba5bda85fd0
Status affected
Version 6.12.34
Version < 6.12.112
Status affected
Version 6.6.94
Version < 6.7
Status affected
Version 6.15.3
Version < 6.16
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.16
Status affected
Version 0
Version < 6.16
Status unaffected
Version <= 6.12.*
Version 6.12.112
Status unaffected
Version <= 6.18.*
Version 6.18.54
Status unaffected
Version <= 7.2.*
Version 7.2.8
Status unaffected
Version <= *
Version 7.3-rc4
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.2% 0.09
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/3d67f155fe5813cfb02a551a9a12d6ea06a902e9
https://git.kernel.org/stable/c/d1152c96a3002e3df6b9a5b007cecaa7b19b4f79
https://git.kernel.org/stable/c/8dc5db3a0e583ea8d31d0613cefd99e93e095c3c
https://git.kernel.org/stable/c/5f0306e731e2f46e91419eae57eee3a241c055e0