7.1
CVE-2026-98169
- EPSS 0.43%
- Veröffentlicht 06.10.2026 08:44:14
- Zuletzt bearbeitet 07.10.2026 07:17:03
- Erkennungen
smb: client: fix potential OOB read in smb3_enum_snapshots()
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix potential OOB read in smb3_enum_snapshots() If snapshot_array_size is smaller than GMT_TOKEN_SIZE, smb3_enum_snapshots() sets ret_data_len to sizeof(struct smb_snapshot_array) without verifying the actual length of the server's reply. Because SMB2_ioctl() places no lower bound on the server-supplied OutputCount and allocates retbuf to exactly that length, a short reply results in ret_data_len exceeding the size of retbuf. The subsequent copy_to_user() then reads past the end of retbuf, leaking adjacent slab memory to userspace. The subsequent clamp check is ineffective as it only reduces ret_data_len. Fix this by rejecting replies shorter than sizeof(struct smb_snapshot_array) with -EIO. Note that the bound is set to the 12-byte struct size rather than the 16-byte MIN_SNAPSHOT_ARRAY_SIZE defined in MS-SMB2 3.3.5.15.1, because 12 bytes is exactly what copy_to_user() attempts to read.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
e02789a53d71334b067ad72eee5d4e88a0158083
Version <
15a221c734b9d044ab769e7e3606b2cab96fb65a
Status
affected
Version
e02789a53d71334b067ad72eee5d4e88a0158083
Version <
74995ee8305a7c4d76ee70d6acd996a75eda3c03
Status
affected
Version
e02789a53d71334b067ad72eee5d4e88a0158083
Version <
210f0f1f67817e7d2348b86b5115a9b85ef5c98b
Status
affected
Version
e02789a53d71334b067ad72eee5d4e88a0158083
Version <
1cdf0d304d820fb13bf0faf532c3459600f9ea43
Status
affected
Version
e02789a53d71334b067ad72eee5d4e88a0158083
Version <
dbe452a905dfe2804647530a9ff3d7e3826ed04d
Status
affected
Version
e02789a53d71334b067ad72eee5d4e88a0158083
Version <
4775c3b7a597907e0b97556c7986fda238a377ae
Status
affected
Version
a94703ff8e3647f8a9a3a92a468450299a7b77e9
Status
affected
Version
82a856f527334ffd69aae26e7dd9e03b19c4a520
Status
affected
Version
25b981bfe192fd208ba04c81f4aa30ffb5141660
Status
affected
Version
4.9.125
Version <
4.10
Status
affected
Version
4.14.68
Version <
4.15
Status
affected
Version
4.18.6
Version <
4.19
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
4.19
Status
affected
Version
0
Version <
4.19
Status
unaffected
Version <=
6.1.*
Version
6.1.189
Status
unaffected
Version <=
6.6.*
Version
6.6.158
Status
unaffected
Version <=
6.12.*
Version
6.12.112
Status
unaffected
Version <=
6.18.*
Version
6.18.54
Status
unaffected
Version <=
7.2.*
Version
7.2.8
Status
unaffected
Version <=
*
Version
7.3-rc4
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.43% | 0.355 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | 7.1 | 2.8 | 4.2 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H
|
https://git.kernel.org/stable/c/15a221c734b9d044ab769e7e3606b2cab96fb65a
https://git.kernel.org/stable/c/74995ee8305a7c4d76ee70d6acd996a75eda3c03
https://git.kernel.org/stable/c/210f0f1f67817e7d2348b86b5115a9b85ef5c98b
https://git.kernel.org/stable/c/1cdf0d304d820fb13bf0faf532c3459600f9ea43
https://git.kernel.org/stable/c/dbe452a905dfe2804647530a9ff3d7e3826ed04d
https://git.kernel.org/stable/c/4775c3b7a597907e0b97556c7986fda238a377ae