{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-98168","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-25T10:25:14.321Z","datePublished":"2026-10-06T08:44:13.534Z","dateUpdated":"2026-10-06T08:44:13.534Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-10-06T08:44:13.534Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: fix reparse buffer bounds in cifs_query_reparse_point()\n\nIn cifs_query_reparse_point(), the start >= end check before casting to\nstruct reparse_data_buffer * only ensures the start pointer is within the\nresponse. It fails to verify that there is enough space remaining for the\nfixed 8-byte header of the structure.\n\nIf a server provides a DataOffset that leaves less than 8 bytes remaining,\nthe check passes, but subsequent reads of ReparseTag and ReparseDataLength\nwill occur out-of-bounds.\n\nFix this by ensuring the remaining space is at least the size of the\nreparse_data_buffer structure before accessing its fields."}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/smb/client/cifssmb.c"],"versions":[{"version":"48ca7139ab7f0bbed95ff7a901ea497017769657","lessThan":"3d67f155fe5813cfb02a551a9a12d6ea06a902e9","status":"affected","versionType":"git"},{"version":"56e84c64fc257a95728ee73165456b025c48d408","lessThan":"d1152c96a3002e3df6b9a5b007cecaa7b19b4f79","status":"affected","versionType":"git"},{"version":"56e84c64fc257a95728ee73165456b025c48d408","lessThan":"8dc5db3a0e583ea8d31d0613cefd99e93e095c3c","status":"affected","versionType":"git"},{"version":"56e84c64fc257a95728ee73165456b025c48d408","lessThan":"5f0306e731e2f46e91419eae57eee3a241c055e0","status":"affected","versionType":"git"},{"version":"848d78e3625f15de09d34a562dc49a98b78a62f3","status":"affected","versionType":"git"},{"version":"c13b779d26b3702fba8f7d5fe757aba5bda85fd0","status":"affected","versionType":"git"},{"version":"6.12.34","lessThan":"6.12.112","status":"affected","versionType":"semver"},{"version":"6.6.94","lessThan":"6.7","status":"affected","versionType":"semver"},{"version":"6.15.3","lessThan":"6.16","status":"affected","versionType":"semver"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/smb/client/cifssmb.c"],"versions":[{"version":"6.16","status":"affected"},{"version":"0","lessThan":"6.16","status":"unaffected","versionType":"semver"},{"version":"6.12.112","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.54","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.8","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc4","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.12.34","versionEndExcluding":"6.12.112"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.16","versionEndExcluding":"6.18.54"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.16","versionEndExcluding":"7.2.8"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.16","versionEndExcluding":"7.3-rc4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.6.94"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.15.3"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/3d67f155fe5813cfb02a551a9a12d6ea06a902e9"},{"url":"https://git.kernel.org/stable/c/d1152c96a3002e3df6b9a5b007cecaa7b19b4f79"},{"url":"https://git.kernel.org/stable/c/8dc5db3a0e583ea8d31d0613cefd99e93e095c3c"},{"url":"https://git.kernel.org/stable/c/5f0306e731e2f46e91419eae57eee3a241c055e0"}],"title":"smb: client: fix reparse buffer bounds in cifs_query_reparse_point()","x_generator":{"engine":"bippy-1.2.0"}}}}