{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-98169","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-25T10:25:14.322Z","datePublished":"2026-10-06T08:44:14.339Z","dateUpdated":"2026-10-07T06:49:19.327Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-10-07T06:49:19.327Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: fix potential OOB read in smb3_enum_snapshots()\n\nIf snapshot_array_size is smaller than GMT_TOKEN_SIZE,\nsmb3_enum_snapshots() sets ret_data_len to\nsizeof(struct smb_snapshot_array) without verifying the actual length\nof the server's reply.\n\nBecause SMB2_ioctl() places no lower bound on the server-supplied\nOutputCount and allocates retbuf to exactly that length, a short reply\nresults in ret_data_len exceeding the size of retbuf. The subsequent\ncopy_to_user() then reads past the end of retbuf, leaking adjacent slab\nmemory to userspace.  The subsequent clamp check is ineffective as it\nonly reduces ret_data_len.\n\nFix this by rejecting replies shorter than\nsizeof(struct smb_snapshot_array) with -EIO. Note that the bound is set\nto the 12-byte struct size rather than the 16-byte\nMIN_SNAPSHOT_ARRAY_SIZE defined in MS-SMB2 3.3.5.15.1, because 12 bytes\nis exactly what copy_to_user() attempts to read."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","baseScore":7.1,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:N - The bad input is the OutputCount field of the SMB2 IOCTL response to FSCTL_SRV_ENUMERATE_SNAPSHOTS, sent by the SMB server over TCP. SMB2_ioctl() rejects only 0 or oversized values and kmemdup()s 1-11 bytes, and smb3_enum_snapshots() then copies 12 bytes from that buffer.\nAC:L - A server that always answers the snapshot FSCTL with OutputCount 1-11 hits the bug every time a caller passes snapshot_array_size < GMT_TOKEN_SIZE, which is the normal first sizing query. No race or memory layout outside the server's control is needed.\nPR:N - The attacker is the SMB server answering the client's request. It needs no account or privilege on the client to send a short IOCTL response.\nUI:R - A victim has to mount the attacker's share, and a process on the client has to issue ioctl(CIFS_ENUMERATE_SNAPSHOTS) on a file there to make smb3_enum_snapshots() run.\nS:U - The out-of-bounds read and the crash both stay inside the client kernel. No VM, IOMMU or other security boundary is crossed.\nC:L - copy_to_user() reads at most 11 bytes past the kmemdup'd retbuf, from the next kmalloc-8 object or the unused tail of a kmalloc-16 object. The leak is small and fixed in size, and it goes to the ioctl caller, not back over the wire.\nI:N - The defect is a read only: retbuf is copied out to user space, and no kernel memory is written out of bounds.\nA:H - With CONFIG_HARDENED_USERCOPY (common on distro and Android kernels), a 12-byte copy_to_user() from a kmalloc-8 retbuf (OutputCount 1-8) fails the heap object check. usercopy_abort() then calls BUG() and the kernel oopses, or panics if panic_on_oops is set. The server can trigger this on every enumeration."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/smb/client/smb2ops.c"],"versions":[{"version":"e02789a53d71334b067ad72eee5d4e88a0158083","lessThan":"15a221c734b9d044ab769e7e3606b2cab96fb65a","status":"affected","versionType":"git"},{"version":"e02789a53d71334b067ad72eee5d4e88a0158083","lessThan":"74995ee8305a7c4d76ee70d6acd996a75eda3c03","status":"affected","versionType":"git"},{"version":"e02789a53d71334b067ad72eee5d4e88a0158083","lessThan":"210f0f1f67817e7d2348b86b5115a9b85ef5c98b","status":"affected","versionType":"git"},{"version":"e02789a53d71334b067ad72eee5d4e88a0158083","lessThan":"1cdf0d304d820fb13bf0faf532c3459600f9ea43","status":"affected","versionType":"git"},{"version":"e02789a53d71334b067ad72eee5d4e88a0158083","lessThan":"dbe452a905dfe2804647530a9ff3d7e3826ed04d","status":"affected","versionType":"git"},{"version":"e02789a53d71334b067ad72eee5d4e88a0158083","lessThan":"4775c3b7a597907e0b97556c7986fda238a377ae","status":"affected","versionType":"git"},{"version":"a94703ff8e3647f8a9a3a92a468450299a7b77e9","status":"affected","versionType":"git"},{"version":"82a856f527334ffd69aae26e7dd9e03b19c4a520","status":"affected","versionType":"git"},{"version":"25b981bfe192fd208ba04c81f4aa30ffb5141660","status":"affected","versionType":"git"},{"version":"4.9.125","lessThan":"4.10","status":"affected","versionType":"semver"},{"version":"4.14.68","lessThan":"4.15","status":"affected","versionType":"semver"},{"version":"4.18.6","lessThan":"4.19","status":"affected","versionType":"semver"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/smb/client/smb2ops.c"],"versions":[{"version":"4.19","status":"affected"},{"version":"0","lessThan":"4.19","status":"unaffected","versionType":"semver"},{"version":"6.1.189","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.158","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.112","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.54","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.8","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc4","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.19","versionEndExcluding":"6.1.189"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.19","versionEndExcluding":"6.6.158"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.19","versionEndExcluding":"6.12.112"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.19","versionEndExcluding":"6.18.54"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.19","versionEndExcluding":"7.2.8"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.19","versionEndExcluding":"7.3-rc4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.9.125"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.14.68"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.18.6"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/15a221c734b9d044ab769e7e3606b2cab96fb65a"},{"url":"https://git.kernel.org/stable/c/74995ee8305a7c4d76ee70d6acd996a75eda3c03"},{"url":"https://git.kernel.org/stable/c/210f0f1f67817e7d2348b86b5115a9b85ef5c98b"},{"url":"https://git.kernel.org/stable/c/1cdf0d304d820fb13bf0faf532c3459600f9ea43"},{"url":"https://git.kernel.org/stable/c/dbe452a905dfe2804647530a9ff3d7e3826ed04d"},{"url":"https://git.kernel.org/stable/c/4775c3b7a597907e0b97556c7986fda238a377ae"}],"title":"smb: client: fix potential OOB read in smb3_enum_snapshots()","x_generator":{"engine":"bippy-1.2.0"}}}}