smb: client: fix next_buffer UAF and NextCommand bounds in compound PDUs
Summary
| CVE | CVE-2026-98171 |
|---|---|
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-10-06 09:17:58 UTC |
| Updated | 2026-10-07 07:17:03 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved: smb: client: fix next_buffer UAF and NextCommand bounds in compound PDUs Fix several related bounds checking and pointer lifecycle issues in receive_encrypted_standard()'s handling of compound encrypted frames: - Clear next_buffer after assigning it to server->bigbuf. A stale next_buffer pointer can lead to a use-after-free on subsequent error paths. - Update pdu_length to the decrypted plaintext size (buf_size). Using the pre-decryption length allows NextCommand to point into stale ciphertext residue. - Reject next_cmd values smaller than MID_HEADER_SIZE(server). - Fix an integer overflow in the upper bound check by verifying pdu_length - next_cmd < MID_HEADER_SIZE(server), ensuring the trailing slice is large enough for a header. |
Risk And Classification
Primary CVSS: v3.1 8.8 HIGH from 416baaa9-dc9f-4396-8d5f-8c081fb06d67
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS: 0.002150000 probability, percentile 0.108120000 (date 2026-10-06)
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | Secondary | 8.8 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
| 3.1 | CNA | DECLARED | 8.8 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
RequiredScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Linux | affected b24df3e30cbf48255db866720fb71f14bf9d2f39 72eaef1f37a3b6bec11c342736834dc3707be3e4 git | Not specified |
| CNA | Linux | Linux | affected b24df3e30cbf48255db866720fb71f14bf9d2f39 491e33144dee872cffda207f6fcb09260728f803 git | Not specified |
| CNA | Linux | Linux | affected b24df3e30cbf48255db866720fb71f14bf9d2f39 8749946579708ea0d339034bb7f423a67dbe89cf git | Not specified |
| CNA | Linux | Linux | affected b24df3e30cbf48255db866720fb71f14bf9d2f39 96c436e4b010711452b2872558938f4ef276492a git | Not specified |
| CNA | Linux | Linux | affected b24df3e30cbf48255db866720fb71f14bf9d2f39 858d5ac22cb889266993e7670f9f0c4f4aeedd78 git | Not specified |
| CNA | Linux | Linux | affected b24df3e30cbf48255db866720fb71f14bf9d2f39 05762c5bc1cfdcac36747994fde2c04387a457f1 git | Not specified |
| CNA | Linux | Linux | affected 4.19 | Not specified |
| CNA | Linux | Linux | unaffected 4.19 semver | Not specified |
| CNA | Linux | Linux | unaffected 6.1.189 6.1.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.6.158 6.6.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.12.112 6.12.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.18.54 6.18.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.2.8 7.2.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.3-rc4 * original_commit_for_fix | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| git.kernel.org/stable/c/72eaef1f37a3b6bec11c342736834dc3707be3e4 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/05762c5bc1cfdcac36747994fde2c04387a457f1 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/8749946579708ea0d339034bb7f423a67dbe89cf | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/491e33144dee872cffda207f6fcb09260728f803 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/858d5ac22cb889266993e7670f9f0c4f4aeedd78 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/96c436e4b010711452b2872558938f4ef276492a | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.