---
id: CVE-2026-98171
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  smb: client: fix next_buffer UAF and NextCommand bounds in compound PDUs

  Fix several related bounds checking and pointer lifecycle issues in
  receive_encrypted_standard…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  smb: client: fix next_buffer UAF and NextCommand bounds in compound PDUs

  Fix several related bounds checking and pointer lifecycle issues in
  receive_encrypted_standard…
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= b24df3e30cbf48255db866720fb71f14bf9d2f39 <
    72eaef1f37a3b6bec11c342736834dc3707be3e4
  - >-
    Linux >= b24df3e30cbf48255db866720fb71f14bf9d2f39 <
    491e33144dee872cffda207f6fcb09260728f803
  - >-
    Linux >= b24df3e30cbf48255db866720fb71f14bf9d2f39 <
    8749946579708ea0d339034bb7f423a67dbe89cf
  - >-
    Linux >= b24df3e30cbf48255db866720fb71f14bf9d2f39 <
    96c436e4b010711452b2872558938f4ef276492a
  - >-
    Linux >= b24df3e30cbf48255db866720fb71f14bf9d2f39 <
    858d5ac22cb889266993e7670f9f0c4f4aeedd78
  - >-
    Linux >= b24df3e30cbf48255db866720fb71f14bf9d2f39 <
    05762c5bc1cfdcac36747994fde2c04387a457f1
  - Linux 4.19
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T09:17:58.773'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-98171'
references:
  - url: 'https://git.kernel.org/stable/c/05762c5bc1cfdcac36747994fde2c04387a457f1'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/491e33144dee872cffda207f6fcb09260728f803'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/72eaef1f37a3b6bec11c342736834dc3707be3e4'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/858d5ac22cb889266993e7670f9f0c4f4aeedd78'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/8749946579708ea0d339034bb7f423a67dbe89cf'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/96c436e4b010711452b2872558938f4ef276492a'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-06T08:50:17.457Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

smb: client: fix next_buffer UAF and NextCommand bounds in compound PDUs

Fix several related bounds checking and pointer lifecycle issues in
receive_encrypted_standard()'s handling of compound encrypted frames:

- Clear next_buffer after assigning it to server->bigbuf. A stale
  next_buffer pointer can lead to a use-after-free on subsequent
  error paths.
- Update pdu_length to the decrypted plaintext size (buf_size). Using
  the pre-decryption length allows NextCommand to point into stale
  ciphertext residue.
- Reject next_cmd values smaller than MID_HEADER_SIZE(server).
- Fix an integer overflow in the upper bound check by verifying
  pdu_length - next_cmd < MID_HEADER_SIZE(server), ensuring the
  trailing slice is large enough for a header.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
