CVE-2026-98170
N/A
Summary
In the Linux kernel, the following vulnerability has been resolved:
smb: client: fix OOB struct field reads in move_smb2_ea_to_cifs()
In move_smb2_ea_to_cifs(), the while (src_size > 0) loop condition is insufficient. It allows iteration to continue even if the remaining src_size is too small to contain a complete smb2_ea_info structure. Consequently, reads of ea_name_length and ea_value_length can occur out-of-bounds.
Fix this by ensuring src_size >= sizeof(*src) before attempting to read any structure fields. Additionally, reject any next_entry_offset that is smaller than sizeof(*src) or that would advance the pointer beyond the available buffer.
Note that for calls where the server returns a malformed EA list, the error returned to userspace changes from -ENODATA (getxattr) or -ERANGE (listxattr) to -EIO. This correctly signals a server protocol error rather than misleadingly indicating "attribute not present" or "output buffer too small".
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 95907fea4fd8ccc736e0a428e52159b4d42b9958 < d3546cecbf81d98bf3b472d341f981eb48c04f47 | affected |
| Linux | Linux | 95907fea4fd8ccc736e0a428e52159b4d42b9958 < 34a3942e787b9c59758115bd65fe1ec89d68c7a4 | affected |
| Linux | Linux | 95907fea4fd8ccc736e0a428e52159b4d42b9958 < 13efcd37a9b3d6ffa1579c3dda3e29c893ed9bca | affected |
| Linux | Linux | 95907fea4fd8ccc736e0a428e52159b4d42b9958 < eeb5ef6083e1cefa2ef75041b5597ff228b8d7bb | affected |
| Linux | Linux | 4.14 | affected |
| Linux | Linux | 0 < 4.14 | unaffected |
| Linux | Linux | 6.12.112 <= 6.12.* | unaffected |
| Linux | Linux | 6.18.54 <= 6.18.* | unaffected |
| Linux | Linux | 7.2.8 <= 7.2.* | unaffected |
| Linux | Linux | 7.3-rc4 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/d3546cecbf81d98bf3b472d341f981eb48c04f47
- https://git.kernel.org/stable/c/34a3942e787b9c59758115bd65fe1ec89d68c7a4
- https://git.kernel.org/stable/c/13efcd37a9b3d6ffa1579c3dda3e29c893ed9bca
- https://git.kernel.org/stable/c/eeb5ef6083e1cefa2ef75041b5597ff228b8d7bb
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.