{"id":"CVE-2026-98169","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: fix potential OOB read in smb3_enum_snapshots()\n\nIf snapshot_array_size is smaller than GMT_TOKEN_SIZE,\nsmb3_enum_snapshots() sets ret_data_len to\nsizeof(s…","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: fix potential OOB read in smb3_enum_snapshots()\n\nIf snapshot_array_size is smaller than GMT_TOKEN_SIZE,\nsmb3_enum_snapshots() sets ret_data_len to\nsizeof(s…","severity":"none","vendor":"Linux","product":"Linux","affected":["Linux >= e02789a53d71334b067ad72eee5d4e88a0158083 < 15a221c734b9d044ab769e7e3606b2cab96fb65a","Linux >= e02789a53d71334b067ad72eee5d4e88a0158083 < 74995ee8305a7c4d76ee70d6acd996a75eda3c03","Linux >= e02789a53d71334b067ad72eee5d4e88a0158083 < 210f0f1f67817e7d2348b86b5115a9b85ef5c98b","Linux >= e02789a53d71334b067ad72eee5d4e88a0158083 < 1cdf0d304d820fb13bf0faf532c3459600f9ea43","Linux >= e02789a53d71334b067ad72eee5d4e88a0158083 < dbe452a905dfe2804647530a9ff3d7e3826ed04d","Linux >= e02789a53d71334b067ad72eee5d4e88a0158083 < 4775c3b7a597907e0b97556c7986fda238a377ae","Linux a94703ff8e3647f8a9a3a92a468450299a7b77e9","Linux 82a856f527334ffd69aae26e7dd9e03b19c4a520","Linux 25b981bfe192fd208ba04c81f4aa30ffb5141660","Linux >= 4.9.125 < 4.10","Linux >= 4.14.68 < 4.15","Linux >= 4.18.6 < 4.19","Linux 4.19"],"published":"2026-10-06","updated":"2026-10-06","sourceUpdated":"2026-10-06T09:17:58.480","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-98169","references":[{"url":"https://git.kernel.org/stable/c/15a221c734b9d044ab769e7e3606b2cab96fb65a","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1cdf0d304d820fb13bf0faf532c3459600f9ea43","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/210f0f1f67817e7d2348b86b5115a9b85ef5c98b","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4775c3b7a597907e0b97556c7986fda238a377ae","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/74995ee8305a7c4d76ee70d6acd996a75eda3c03","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/dbe452a905dfe2804647530a9ff3d7e3826ed04d","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-06T08:50:17.459Z","slug":"CVE-2026-98169","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: fix potential OOB read in smb3_enum_snapshots()\n\nIf snapshot_array_size is smaller than GMT_TOKEN_SIZE,\nsmb3_enum_snapshots() sets ret_data_len to\nsizeof(struct smb_snapshot_array) without verifying the actual length\nof the server's reply.\n\nBecause SMB2_ioctl() places no lower bound on the server-supplied\nOutputCount and allocates retbuf to exactly that length, a short reply\nresults in ret_data_len exceeding the size of retbuf. The subsequent\ncopy_to_user() then reads past the end of retbuf, leaking adjacent slab\nmemory to userspace.  The subsequent clamp check is ineffective as it\nonly reduces ret_data_len.\n\nFix this by rejecting replies shorter than\nsizeof(struct smb_snapshot_array) with -EIO. Note that the bound is set\nto the 12-byte struct size rather than the 16-byte\nMIN_SNAPSHOT_ARRAY_SIZE defined in MS-SMB2 3.3.5.15.1, because 12 bytes\nis exactly what copy_to_user() attempts to read.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}