{"api_version":"1","generated_at":"2026-10-08T07:22:58+00:00","cve":"CVE-2026-98171","urls":{"html":"https://cve.report/CVE-2026-98171","api":"https://cve.report/api/cve/CVE-2026-98171.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-98171","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-98171"},"summary":{"title":"smb: client: fix next_buffer UAF and NextCommand bounds in compound PDUs","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: fix next_buffer UAF and NextCommand bounds in compound PDUs\n\nFix several related bounds checking and pointer lifecycle issues in\nreceive_encrypted_standard()'s handling of compound encrypted frames:\n\n- Clear next_buffer after assigning it to server->bigbuf. A stale\n  next_buffer pointer can lead to a use-after-free on subsequent\n  error paths.\n- Update pdu_length to the decrypted plaintext size (buf_size). Using\n  the pre-decryption length allows NextCommand to point into stale\n  ciphertext residue.\n- Reject next_cmd values smaller than MID_HEADER_SIZE(server).\n- Fix an integer overflow in the upper bound check by verifying\n  pdu_length - next_cmd < MID_HEADER_SIZE(server), ensuring the\n  trailing slice is large enough for a header.","state":"PUBLISHED","assigner":"Linux","published_at":"2026-10-06 09:17:58","updated_at":"2026-10-07 07:17:03"},"problem_types":[],"metrics":[{"version":"3.1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","score":"8.8","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"8.8","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","data":{"baseScore":8.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","version":"3.1"}}],"references":[{"url":"https://git.kernel.org/stable/c/72eaef1f37a3b6bec11c342736834dc3707be3e4","name":"https://git.kernel.org/stable/c/72eaef1f37a3b6bec11c342736834dc3707be3e4","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/05762c5bc1cfdcac36747994fde2c04387a457f1","name":"https://git.kernel.org/stable/c/05762c5bc1cfdcac36747994fde2c04387a457f1","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/8749946579708ea0d339034bb7f423a67dbe89cf","name":"https://git.kernel.org/stable/c/8749946579708ea0d339034bb7f423a67dbe89cf","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/491e33144dee872cffda207f6fcb09260728f803","name":"https://git.kernel.org/stable/c/491e33144dee872cffda207f6fcb09260728f803","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/858d5ac22cb889266993e7670f9f0c4f4aeedd78","name":"https://git.kernel.org/stable/c/858d5ac22cb889266993e7670f9f0c4f4aeedd78","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/96c436e4b010711452b2872558938f4ef276492a","name":"https://git.kernel.org/stable/c/96c436e4b010711452b2872558938f4ef276492a","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-98171","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-98171","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected b24df3e30cbf48255db866720fb71f14bf9d2f39 72eaef1f37a3b6bec11c342736834dc3707be3e4 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected b24df3e30cbf48255db866720fb71f14bf9d2f39 491e33144dee872cffda207f6fcb09260728f803 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected b24df3e30cbf48255db866720fb71f14bf9d2f39 8749946579708ea0d339034bb7f423a67dbe89cf git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected b24df3e30cbf48255db866720fb71f14bf9d2f39 96c436e4b010711452b2872558938f4ef276492a git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected b24df3e30cbf48255db866720fb71f14bf9d2f39 858d5ac22cb889266993e7670f9f0c4f4aeedd78 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected b24df3e30cbf48255db866720fb71f14bf9d2f39 05762c5bc1cfdcac36747994fde2c04387a457f1 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 4.19","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 4.19 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.1.189 6.1.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.6.158 6.6.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.12.112 6.12.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.18.54 6.18.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2.8 7.2.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.3-rc4 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"98171","cve":"CVE-2026-98171","epss":"0.002150000","percentile":"0.108120000","score_date":"2026-10-06","updated_at":"2026-10-07 00:14:55"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["fs/smb/client/smb2ops.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"72eaef1f37a3b6bec11c342736834dc3707be3e4","status":"affected","version":"b24df3e30cbf48255db866720fb71f14bf9d2f39","versionType":"git"},{"lessThan":"491e33144dee872cffda207f6fcb09260728f803","status":"affected","version":"b24df3e30cbf48255db866720fb71f14bf9d2f39","versionType":"git"},{"lessThan":"8749946579708ea0d339034bb7f423a67dbe89cf","status":"affected","version":"b24df3e30cbf48255db866720fb71f14bf9d2f39","versionType":"git"},{"lessThan":"96c436e4b010711452b2872558938f4ef276492a","status":"affected","version":"b24df3e30cbf48255db866720fb71f14bf9d2f39","versionType":"git"},{"lessThan":"858d5ac22cb889266993e7670f9f0c4f4aeedd78","status":"affected","version":"b24df3e30cbf48255db866720fb71f14bf9d2f39","versionType":"git"},{"lessThan":"05762c5bc1cfdcac36747994fde2c04387a457f1","status":"affected","version":"b24df3e30cbf48255db866720fb71f14bf9d2f39","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["fs/smb/client/smb2ops.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"4.19"},{"lessThan":"4.19","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"6.1.*","status":"unaffected","version":"6.1.189","versionType":"semver"},{"lessThanOrEqual":"6.6.*","status":"unaffected","version":"6.6.158","versionType":"semver"},{"lessThanOrEqual":"6.12.*","status":"unaffected","version":"6.12.112","versionType":"semver"},{"lessThanOrEqual":"6.18.*","status":"unaffected","version":"6.18.54","versionType":"semver"},{"lessThanOrEqual":"7.2.*","status":"unaffected","version":"7.2.8","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.3-rc4","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.1.189","versionStartIncluding":"4.19","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.6.158","versionStartIncluding":"4.19","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.12.112","versionStartIncluding":"4.19","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.18.54","versionStartIncluding":"4.19","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2.8","versionStartIncluding":"4.19","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.3-rc4","versionStartIncluding":"4.19","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: fix next_buffer UAF and NextCommand bounds in compound PDUs\n\nFix several related bounds checking and pointer lifecycle issues in\nreceive_encrypted_standard()'s handling of compound encrypted frames:\n\n- Clear next_buffer after assigning it to server->bigbuf. A stale\n  next_buffer pointer can lead to a use-after-free on subsequent\n  error paths.\n- Update pdu_length to the decrypted plaintext size (buf_size). Using\n  the pre-decryption length allows NextCommand to point into stale\n  ciphertext residue.\n- Reject next_cmd values smaller than MID_HEADER_SIZE(server).\n- Fix an integer overflow in the upper bound check by verifying\n  pdu_length - next_cmd < MID_HEADER_SIZE(server), ensuring the\n  trailing slice is large enough for a header."}],"metrics":[{"cvssV3_1":{"baseScore":8.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","version":"3.1"},"scenarios":[{"lang":"en","value":"AV:N - The malformed input is an encrypted SMB2 compound response (TRANSFORM header, inner NextCommand chain) sent by the SMB server over TCP/445 and parsed by receive_encrypted_standard() via cifs_demultiplex_thread -> smb3_receive_transform, so the bytes that cause the bug arrive over a routable network protocol.\nAC:L - The malicious server fully controls the sequence: a compound response whose first PDU has non-zero NextCommand, then a trailing PDU with NextCommand=0 and STATUS_PENDING or an unmatched MID with a bad header makes cifs_handle_standard() return non-zero, freeing the stale next_buffer every time; no race or external state is involved.\nPR:N - The attacker is the SMB server endpoint. It needs no account or privilege on the victim client, because it negotiates the session and encryption keys itself and so can produce valid encrypted frames.\nUI:R - A victim user or admin has to mount (or be redirected by DFS to) a share hosted on the attacker-controlled server before the client receives any encrypted compound response, so user action is required.\nS:U - The corruption is confined to the client kernel's own cifs receive buffers and slab/mempool objects, which is a standard kernel compromise and does not cross into a separate security authority.\nC:H - The error path frees server->smallbuf/bigbuf while it is still installed, which is a UAF on a kernel heap object. The object can be reallocated and its contents processed as SMB responses, a primitive usable for kernel memory disclosure.\nI:H - After the bad free, allocate_buffers() keeps the dangling smallbuf/bigbuf, and cifs_read_from_socket() writes the next frame's server-chosen bytes into the freed object (with a later double free), giving an attacker-controlled write into reallocated kernel memory.\nA:H - The use-after-free and double free of the cifs receive buffers in the demultiplex thread can corrupt the slab or mempool, causing a kernel oops or panic on the client and making every mount on that host unavailable."}]}],"providerMetadata":{"dateUpdated":"2026-10-07T06:49:20.472Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/72eaef1f37a3b6bec11c342736834dc3707be3e4"},{"url":"https://git.kernel.org/stable/c/491e33144dee872cffda207f6fcb09260728f803"},{"url":"https://git.kernel.org/stable/c/8749946579708ea0d339034bb7f423a67dbe89cf"},{"url":"https://git.kernel.org/stable/c/96c436e4b010711452b2872558938f4ef276492a"},{"url":"https://git.kernel.org/stable/c/858d5ac22cb889266993e7670f9f0c4f4aeedd78"},{"url":"https://git.kernel.org/stable/c/05762c5bc1cfdcac36747994fde2c04387a457f1"}],"title":"smb: client: fix next_buffer UAF and NextCommand bounds in compound PDUs","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-98171","datePublished":"2026-10-06T08:44:15.927Z","dateReserved":"2026-09-25T10:25:14.322Z","dateUpdated":"2026-10-07T06:49:20.472Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-10-06 09:17:58","lastModifiedDate":"2026-10-07 07:17:03","problem_types":[],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"98171","Ordinal":"1","Title":"smb: client: fix next_buffer UAF and NextCommand bounds in compo","CVE":"CVE-2026-98171","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"98171","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: fix next_buffer UAF and NextCommand bounds in compound PDUs\n\nFix several related bounds checking and pointer lifecycle issues in\nreceive_encrypted_standard()'s handling of compound encrypted frames:\n\n- Clear next_buffer after assigning it to server->bigbuf. A stale\n  next_buffer pointer can lead to a use-after-free on subsequent\n  error paths.\n- Update pdu_length to the decrypted plaintext size (buf_size). Using\n  the pre-decryption length allows NextCommand to point into stale\n  ciphertext residue.\n- Reject next_cmd values smaller than MID_HEADER_SIZE(server).\n- Fix an integer overflow in the upper bound check by verifying\n  pdu_length - next_cmd < MID_HEADER_SIZE(server), ensuring the\n  trailing slice is large enough for a header.","Type":"Description","Title":"smb: client: fix next_buffer UAF and NextCommand bounds in compo"}]}}}