CVE-2026-98171

Source
https://cve.org/CVERecord?id=CVE-2026-98171
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98171.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-98171
Downstream
Published
2026-10-06T08:44:15Z
Modified
2026-10-08T02:52:52Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
smb: client: fix next_buffer UAF and NextCommand bounds in compound PDUs
Details

In the Linux kernel, the following vulnerability has been resolved:

smb: client: fix next_buffer UAF and NextCommand bounds in compound PDUs

Fix several related bounds checking and pointer lifecycle issues in receive_encrypted_standard()'s handling of compound encrypted frames:

  • Clear next_buffer after assigning it to server->bigbuf. A stale next_buffer pointer can lead to a use-after-free on subsequent error paths.
  • Update pdu_length to the decrypted plaintext size (buf_size). Using the pre-decryption length allows NextCommand to point into stale ciphertext residue.
  • Reject next_cmd values smaller than MID_HEADER_SIZE(server).
  • Fix an integer overflow in the upper bound check by verifying pdu_length - next_cmd < MID_HEADER_SIZE(server), ensuring the trailing slice is large enough for a header.
Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98171.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
b24df3e30cbf48255db866720fb71f14bf9d2f39
Fixed
72eaef1f37a3b6bec11c342736834dc3707be3e4
Fixed
491e33144dee872cffda207f6fcb09260728f803
Fixed
8749946579708ea0d339034bb7f423a67dbe89cf
Fixed
96c436e4b010711452b2872558938f4ef276492a
Fixed
858d5ac22cb889266993e7670f9f0c4f4aeedd78
Fixed
05762c5bc1cfdcac36747994fde2c04387a457f1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98171.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.19.0
Fixed
6.1.189
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.158
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.112
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.54
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98171.json"