{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-98318","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-25T10:25:14.340Z","datePublished":"2026-10-06T08:46:13.140Z","dateUpdated":"2026-10-07T06:50:00.705Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-10-07T06:50:00.705Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: validate absolute native symlink targets before NT fixups\n\nWith symlinkroot unset, an absolute target is copied without conversion\nto an NT drive path. Later code still assumes an NT prefix is present\nwhen modifying the target and calculating the print name length.\n\nFor \"/ab\", this causes two failures: sym[5] and path[5] are written\npast their allocations, and plen -= 2 * poff subtracts an assumed\n8-byte prefix from a 6-byte UTF-16 target, wrapping u16 plen to 65534.\nThat underflow causes another overflow: memcpy() copies 65534 bytes\ninto a 24-byte buffer. A user with write access to a mounted share\ncan trigger these bugs with default settings.\n\nValidate the NT drive prefix, including an ASCII drive letter, before\naccessing fixed offsets or subtracting the prefix length."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The malformed input is the symlink target string a local user passes to symlink(2) on a CIFS mount (cifs_symlink -> create_reparse_symlink -> create_native_symlink); the SMB server supplies none of the bad data, and the overflow happens before any request is sent.\nAC:L - With default options (reparse_type defaults to NFS so cifs_symlink_type() returns NATIVE, symlinkroot unset) a target like \"/ab\" deterministically triggers the plen underflow; detect_directory_symlink_target() returns 0 for absolute targets, so nothing on the path depends on state outside the attacker's control.\nPR:L - The attacker needs only an ordinary local account with write access to a directory on an already-mounted CIFS share whose server advertises FILE_SUPPORTS_REPARSE_POINTS; cifs is not mountable from user namespaces, so no further privilege is gained there.\nUI:N - The attacker triggers the bug entirely through their own symlink(2) call; no victim action is needed beyond the share already being mounted.\nS:U - Heap corruption in the CIFS client stays within the local kernel's security authority; this is ordinary local privilege escalation or crash with no VM or IOMMU boundary crossed.\nC:H - memcpy(buf->PathBuffer, path+poff, plen) reads 65534 bytes past the small UTF-16 path allocation, and the matching heap overflow can be groomed into read primitives over adjacent slab objects.\nI:H - Out-of-bounds heap writes: sym[5]/path[5] past their allocations, and a 65534-byte memcpy into a 24-byte kzalloc buffer after u16 plen and len wrap, corrupting adjacent slab objects in a way usable for control-flow hijack.\nA:H - The 64 KiB overflow of the kmalloc buffer corrupts large amounts of slab memory and reliably oopses or panics the kernel, and any user with write access to the share can repeat it."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/smb/client/reparse.c"],"versions":[{"version":"3363da82e02f1bddc54faa92ea430c6532e2cd2e","lessThan":"6913ff607c2bc8694193e1fcc40bf16d75f35f16","status":"affected","versionType":"git"},{"version":"3363da82e02f1bddc54faa92ea430c6532e2cd2e","lessThan":"23c240d9509e15f72e4112fc95f0160ab32ec430","status":"affected","versionType":"git"},{"version":"b6ea7b6c6be65149ab6b8e37a9dd1671f76add1b","status":"affected","versionType":"git"},{"version":"6.15.6","lessThan":"6.16","status":"affected","versionType":"semver"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/smb/client/reparse.c"],"versions":[{"version":"6.16","status":"affected"},{"version":"0","lessThan":"6.16","status":"unaffected","versionType":"semver"},{"version":"7.2.8","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc4","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.16","versionEndExcluding":"7.2.8"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.16","versionEndExcluding":"7.3-rc4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.15.6"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/6913ff607c2bc8694193e1fcc40bf16d75f35f16"},{"url":"https://git.kernel.org/stable/c/23c240d9509e15f72e4112fc95f0160ab32ec430"}],"title":"smb: client: validate absolute native symlink targets before NT fixups","x_generator":{"engine":"bippy-1.2.0"}}}}