{"id":"AZL-106338","summary":"CVE-2026-98168 affecting package kernel 6.6.157.1-1","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: fix reparse buffer bounds in cifs_query_reparse_point()\n\nIn cifs_query_reparse_point(), the start \u003e= end check before casting to\nstruct reparse_data_buffer * only ensures the start pointer is within the\nresponse. It fails to verify that there is enough space remaining for the\nfixed 8-byte header of the structure.\n\nIf a server provides a DataOffset that leaves less than 8 bytes remaining,\nthe check passes, but subsequent reads of ReparseTag and ReparseDataLength\nwill occur out-of-bounds.\n\nFix this by ensuring the remaining space is at least the size of the\nreparse_data_buffer structure before accessing its fields.","modified":"2026-10-07T14:17:02.003759710Z","published":"2026-10-06T09:17:58Z","upstream":["CVE-2026-98168"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-98168"}],"affected":[{"package":{"name":"kernel","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.6.157.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-106338.json"}}],"schema_version":"1.9.0"}