{"id":"AZL-106017","summary":"CVE-2026-98167 affecting package kernel 6.6.157.1-1","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: fix server-\u003etotal_read for compound encrypted PDUs\n\nIn receive_encrypted_standard(), server-\u003etotal_read is left at the\nfull decrypted frame size when walking sub-PDUs of a compound encrypted\nframe. As a result, cifs_handle_standard() passes this full size\nto smb2_check_message(), causing the PDU length guards to incorrectly\nvalidate the entire compound frame instead of the current sub-PDU.\n\nThis allows truncated non-last sub-PDUs to bypass length validation,\nleading to out-of-bounds reads in smb2_get_data_area_len().\n\nFix this by setting server-\u003etotal_read to the true length of the\ncurrent sub-PDU: next_cmd for non-last sub-PDUs, and the remaining\npdu_length for the last one.","modified":"2026-10-07T14:16:52.112135969Z","published":"2026-10-06T09:17:58Z","upstream":["CVE-2026-98167"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-98167"}],"affected":[{"package":{"name":"kernel","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.6.157.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-106017.json"}}],"schema_version":"1.9.0"}