Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-98167— smb: client: fix server->total_read for compound encrypted PDUs

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Linux 内核中,已修复以下漏洞: smb:客户端:修复复合加密 PDU 中 server->total_read 的问题 在 函数中,当遍历复合加密帧的子 PDU(sub-PDUs)时, 被错误地保留为整个解密后帧的大小。因此, 将该完整大小传递给 ,导致 PDU 长度检查机制错误地对整个复合帧而非当前子 PDU 进行验证。 这使得截断的非最后子 PDU 能够绕过长度验证,进而在 中引发越界读取漏洞。 修复方法是将 设置为当前子 PDU 的实际长度:对于非最后子 PDU,设置为 ;对于最后子 PDU,设置为

AI Predicted 7.5 Difficulty: Moderate EPSS 0.22% · P11

Possible ATT&CK Techniques 1 AI

T1210 · Exploitation of Remote Services

Affected Version Matrix 14

VendorProduct Version RangeStatus
Linux Linux b24df3e30cbf48255db866720fb71f14bf9d2f39< 8703539d22fdbc13dd2db090ee199c3a427b8ea0 affected
b24df3e30cbf48255db866720fb71f14bf9d2f39< e78fc1d240b27349b45a0f1c3e3c2c401d7e230d affected
b24df3e30cbf48255db866720fb71f14bf9d2f39< a46eb242e9eef3a3897d166748b23303c516e870 affected
b24df3e30cbf48255db866720fb71f14bf9d2f39< ebb8a075fdc7af3d196a4f158a0e18dbc394c0e3 affected
b24df3e30cbf48255db866720fb71f14bf9d2f39< 282b72f9a7ef31296c48366db4128882999cc048 affected
b24df3e30cbf48255db866720fb71f14bf9d2f39< f73726b83e4756fdaa099e1bc1143293bd57ad79 affected
4.19 affected
< 4.19 unaffected
… +6 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-98167

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
smb: client: fix server->total_read for compound encrypted PDUs
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix server->total_read for compound encrypted PDUs In receive_encrypted_standard(), server->total_read is left at the full decrypted frame size when walking sub-PDUs of a compound encrypted frame. As a result, cifs_handle_standard() passes this full size to smb2_check_message(), causing the PDU length guards to incorrectly validate the entire compound frame instead of the current sub-PDU. This allows truncated non-last sub-PDUs to bypass length validation, leading to out-of-bounds reads in smb2_get_data_area_len(). Fix this by setting server->total_read to the true length of the current sub-PDU: next_cmd for non-last sub-PDUs, and the remaining pdu_length for the last one.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux b24df3e30cbf48255db866720fb71f14bf9d2f39 ~ 8703539d22fdbc13dd2db090ee199c3a427b8ea0 -
Linux Linux 4.19 -

II. Public POCs for CVE-2026-98167

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-98167

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-98167 (6)

Same Patch Batch · Linux · 2026-10-06 · 208 CVEs total

CVE-2026-98323 9.8 CRITICAL RDMA/siw: Bound fragmented header copies by the remaining length
CVE-2026-98365 9.8 CRITICAL RDMA/rxe: Fix integer overflow in mr_check_range() leading to OOB access
CVE-2026-98282 8.8 HIGH powerpc/iommu: Fix the overflow validation in iommu_tce_check_ioba
CVE-2026-98283 8.8 HIGH KVM: PPC: Book3S HV: fix use-after-free in kvmhv_emulate_tlbie_all_lpid()
CVE-2026-98339 8.8 HIGH wifi: cfg80211: don't filter by BSS type when removing stale entries
CVE-2026-98171 8.8 HIGH smb: client: fix next_buffer UAF and NextCommand bounds in compound PDUs
CVE-2026-98261 8.1 HIGH cifs: Fix server use-after-free in cifs_chan_skip_or_disable()
CVE-2026-98357 8.1 HIGH IB/isert: wait for deferred control PDU completions before releasing the connection
CVE-2026-98239 8.1 HIGH net: lan743x: fix RX checksum use-after-free
CVE-2026-98341 7.8 HIGH wifi: cfg80211: don't free driver-owned scan requests
CVE-2026-98324 7.8 HIGH dmaengine: pxa: fix double counting of the hw descriptors
CVE-2026-98228 7.8 HIGH mips: select CONFIG_WEAK_REORDERING_BEYOND_LLSC from CONFIG_EYEQ
CVE-2026-98229 7.8 HIGH xfrm: save input state data before secpath resets
CVE-2026-98320 7.8 HIGH netfilter: flowtable: hold reference on ct until flow is released
CVE-2026-98318 7.8 HIGH smb: client: validate absolute native symlink targets before NT fixups
CVE-2026-98315 7.8 HIGH ntfs: protect runlist updates with the runlist lock
CVE-2026-98260 7.8 HIGH exec: Cleanup POSIX timers right after de_thread()
CVE-2026-98256 7.8 HIGH signal: Prevent exec() race
CVE-2026-98258 7.8 HIGH posix-cpu-timers: Prevent freeing a timer which is queued on the expiry list
CVE-2026-98254 7.8 HIGH swiotlb: use the adjusted address for the highmem page lookup

Showing top 20 of 208 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-98167

No comments yet


Leave a comment