{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-98171","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-25T10:25:14.322Z","datePublished":"2026-10-06T08:44:15.927Z","dateUpdated":"2026-10-07T06:49:20.472Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-10-07T06:49:20.472Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: fix next_buffer UAF and NextCommand bounds in compound PDUs\n\nFix several related bounds checking and pointer lifecycle issues in\nreceive_encrypted_standard()'s handling of compound encrypted frames:\n\n- Clear next_buffer after assigning it to server->bigbuf. A stale\n  next_buffer pointer can lead to a use-after-free on subsequent\n  error paths.\n- Update pdu_length to the decrypted plaintext size (buf_size). Using\n  the pre-decryption length allows NextCommand to point into stale\n  ciphertext residue.\n- Reject next_cmd values smaller than MID_HEADER_SIZE(server).\n- Fix an integer overflow in the upper bound check by verifying\n  pdu_length - next_cmd < MID_HEADER_SIZE(server), ensuring the\n  trailing slice is large enough for a header."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:N - The malformed input is an encrypted SMB2 compound response (TRANSFORM header, inner NextCommand chain) sent by the SMB server over TCP/445 and parsed by receive_encrypted_standard() via cifs_demultiplex_thread -> smb3_receive_transform, so the bytes that cause the bug arrive over a routable network protocol.\nAC:L - The malicious server fully controls the sequence: a compound response whose first PDU has non-zero NextCommand, then a trailing PDU with NextCommand=0 and STATUS_PENDING or an unmatched MID with a bad header makes cifs_handle_standard() return non-zero, freeing the stale next_buffer every time; no race or external state is involved.\nPR:N - The attacker is the SMB server endpoint. It needs no account or privilege on the victim client, because it negotiates the session and encryption keys itself and so can produce valid encrypted frames.\nUI:R - A victim user or admin has to mount (or be redirected by DFS to) a share hosted on the attacker-controlled server before the client receives any encrypted compound response, so user action is required.\nS:U - The corruption is confined to the client kernel's own cifs receive buffers and slab/mempool objects, which is a standard kernel compromise and does not cross into a separate security authority.\nC:H - The error path frees server->smallbuf/bigbuf while it is still installed, which is a UAF on a kernel heap object. The object can be reallocated and its contents processed as SMB responses, a primitive usable for kernel memory disclosure.\nI:H - After the bad free, allocate_buffers() keeps the dangling smallbuf/bigbuf, and cifs_read_from_socket() writes the next frame's server-chosen bytes into the freed object (with a later double free), giving an attacker-controlled write into reallocated kernel memory.\nA:H - The use-after-free and double free of the cifs receive buffers in the demultiplex thread can corrupt the slab or mempool, causing a kernel oops or panic on the client and making every mount on that host unavailable."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/smb/client/smb2ops.c"],"versions":[{"version":"b24df3e30cbf48255db866720fb71f14bf9d2f39","lessThan":"72eaef1f37a3b6bec11c342736834dc3707be3e4","status":"affected","versionType":"git"},{"version":"b24df3e30cbf48255db866720fb71f14bf9d2f39","lessThan":"491e33144dee872cffda207f6fcb09260728f803","status":"affected","versionType":"git"},{"version":"b24df3e30cbf48255db866720fb71f14bf9d2f39","lessThan":"8749946579708ea0d339034bb7f423a67dbe89cf","status":"affected","versionType":"git"},{"version":"b24df3e30cbf48255db866720fb71f14bf9d2f39","lessThan":"96c436e4b010711452b2872558938f4ef276492a","status":"affected","versionType":"git"},{"version":"b24df3e30cbf48255db866720fb71f14bf9d2f39","lessThan":"858d5ac22cb889266993e7670f9f0c4f4aeedd78","status":"affected","versionType":"git"},{"version":"b24df3e30cbf48255db866720fb71f14bf9d2f39","lessThan":"05762c5bc1cfdcac36747994fde2c04387a457f1","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/smb/client/smb2ops.c"],"versions":[{"version":"4.19","status":"affected"},{"version":"0","lessThan":"4.19","status":"unaffected","versionType":"semver"},{"version":"6.1.189","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.158","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.112","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.54","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.8","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc4","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.19","versionEndExcluding":"6.1.189"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.19","versionEndExcluding":"6.6.158"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.19","versionEndExcluding":"6.12.112"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.19","versionEndExcluding":"6.18.54"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.19","versionEndExcluding":"7.2.8"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.19","versionEndExcluding":"7.3-rc4"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/72eaef1f37a3b6bec11c342736834dc3707be3e4"},{"url":"https://git.kernel.org/stable/c/491e33144dee872cffda207f6fcb09260728f803"},{"url":"https://git.kernel.org/stable/c/8749946579708ea0d339034bb7f423a67dbe89cf"},{"url":"https://git.kernel.org/stable/c/96c436e4b010711452b2872558938f4ef276492a"},{"url":"https://git.kernel.org/stable/c/858d5ac22cb889266993e7670f9f0c4f4aeedd78"},{"url":"https://git.kernel.org/stable/c/05762c5bc1cfdcac36747994fde2c04387a457f1"}],"title":"smb: client: fix next_buffer UAF and NextCommand bounds in compound PDUs","x_generator":{"engine":"bippy-1.2.0"}}}}