{"id":"CVE-2026-98318","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: validate absolute native symlink targets before NT fixups\n\nWith symlinkroot unset, an absolute target is copied without conversion\nto an NT drive path","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: validate absolute native symlink targets before NT fixups\n\nWith symlinkroot unset, an absolute target is copied without conversion\nto an NT drive path. Lat…","severity":"none","vendor":"Linux","product":"Linux","affected":["Linux >= 3363da82e02f1bddc54faa92ea430c6532e2cd2e < 6913ff607c2bc8694193e1fcc40bf16d75f35f16","Linux >= 3363da82e02f1bddc54faa92ea430c6532e2cd2e < 23c240d9509e15f72e4112fc95f0160ab32ec430","Linux b6ea7b6c6be65149ab6b8e37a9dd1671f76add1b","Linux >= 6.15.6 < 6.16","Linux 6.16"],"published":"2026-10-06","updated":"2026-10-06","sourceUpdated":"2026-10-06T09:18:23.670","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-98318","references":[{"url":"https://git.kernel.org/stable/c/23c240d9509e15f72e4112fc95f0160ab32ec430","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6913ff607c2bc8694193e1fcc40bf16d75f35f16","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-06T08:50:17.408Z","slug":"CVE-2026-98318","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: validate absolute native symlink targets before NT fixups\n\nWith symlinkroot unset, an absolute target is copied without conversion\nto an NT drive path. Later code still assumes an NT prefix is present\nwhen modifying the target and calculating the print name length.\n\nFor \"/ab\", this causes two failures: sym[5] and path[5] are written\npast their allocations, and plen -= 2 * poff subtracts an assumed\n8-byte prefix from a 6-byte UTF-16 target, wrapping u16 plen to 65534.\nThat underflow causes another overflow: memcpy() copies 65534 bytes\ninto a 24-byte buffer. A user with write access to a mounted share\ncan trigger these bugs with default settings.\n\nValidate the NT drive prefix, including an ASCII drive letter, before\naccessing fixed offsets or subtracting the prefix length.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}