{"id":"CVE-2026-98168","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: fix reparse buffer bounds in cifs_query_reparse_point()\n\nIn cifs_query_reparse_point(), the start >= end check before casting to\nstruct reparse_data_buffer…","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: fix reparse buffer bounds in cifs_query_reparse_point()\n\nIn cifs_query_reparse_point(), the start >= end check before casting to\nstruct reparse_data_buffer…","severity":"medium","vendor":"Linux","product":"Linux","affected":["Linux >= 48ca7139ab7f0bbed95ff7a901ea497017769657 < 3d67f155fe5813cfb02a551a9a12d6ea06a902e9","Linux >= 56e84c64fc257a95728ee73165456b025c48d408 < d1152c96a3002e3df6b9a5b007cecaa7b19b4f79","Linux >= 56e84c64fc257a95728ee73165456b025c48d408 < 8dc5db3a0e583ea8d31d0613cefd99e93e095c3c","Linux >= 56e84c64fc257a95728ee73165456b025c48d408 < 5f0306e731e2f46e91419eae57eee3a241c055e0","Linux 848d78e3625f15de09d34a562dc49a98b78a62f3","Linux c13b779d26b3702fba8f7d5fe757aba5bda85fd0","Linux >= 6.12.34 < 6.12.112","Linux >= 6.6.94 < 6.7","Linux >= 6.15.3 < 6.16","Linux 6.16"],"published":"2026-10-06","updated":"2026-10-06","sourceUpdated":"2026-10-06T09:17:58.333","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-98168","references":[{"url":"https://git.kernel.org/stable/c/3d67f155fe5813cfb02a551a9a12d6ea06a902e9","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5f0306e731e2f46e91419eae57eee3a241c055e0","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8dc5db3a0e583ea8d31d0613cefd99e93e095c3c","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d1152c96a3002e3df6b9a5b007cecaa7b19b4f79","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-98168.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-98168"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2546433"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-98168"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-98168"},{"url":"https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-98168.mbox"}],"tags":["nvd","cve.org","csaf","vex","red-hat"],"ingestedAt":"2026-10-06T08:50:17.458Z","cvss":5.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","cvssSource":"vendor","cwe":["CWE-125"],"slug":"CVE-2026-98168","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: fix reparse buffer bounds in cifs_query_reparse_point()\n\nIn cifs_query_reparse_point(), the start >= end check before casting to\nstruct reparse_data_buffer * only ensures the start pointer is within the\nresponse. It fails to verify that there is enough space remaining for the\nfixed 8-byte header of the structure.\n\nIf a server provides a DataOffset that leaves less than 8 bytes remaining,\nthe check passes, but subsequent reads of ReparseTag and ReparseDataLength\nwill occur out-of-bounds.\n\nFix this by ensuring the remaining space is at least the size of the\nreparse_data_buffer structure before accessing its fields.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Moderate · affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4 · no fix planned: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4 · updated 2026-10-06 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-98168.json)","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":30.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":217224,"id":"CVE-2026-98168","ts":1791360774233,"field":"cvss","old":null,"new":"5.5"},{"seq":217223,"id":"CVE-2026-98168","ts":1791360774233,"field":"severity","old":"none","new":"medium"}]}