{"id":"CVE-2026-98169","summary":"smb: client: fix potential OOB read in smb3_enum_snapshots()","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: fix potential OOB read in smb3_enum_snapshots()\n\nIf snapshot_array_size is smaller than GMT_TOKEN_SIZE,\nsmb3_enum_snapshots() sets ret_data_len to\nsizeof(struct smb_snapshot_array) without verifying the actual length\nof the server's reply.\n\nBecause SMB2_ioctl() places no lower bound on the server-supplied\nOutputCount and allocates retbuf to exactly that length, a short reply\nresults in ret_data_len exceeding the size of retbuf. The subsequent\ncopy_to_user() then reads past the end of retbuf, leaking adjacent slab\nmemory to userspace.  The subsequent clamp check is ineffective as it\nonly reduces ret_data_len.\n\nFix this by rejecting replies shorter than\nsizeof(struct smb_snapshot_array) with -EIO. Note that the bound is set\nto the 12-byte struct size rather than the 16-byte\nMIN_SNAPSHOT_ARRAY_SIZE defined in MS-SMB2 3.3.5.15.1, because 12 bytes\nis exactly what copy_to_user() attempts to read.","modified":"2026-10-08T02:52:52.492108238Z","published":"2026-10-06T08:44:14.339Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98169.json","cna_assigner":"Linux"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/15a221c734b9d044ab769e7e3606b2cab96fb65a"},{"type":"WEB","url":"https://git.kernel.org/stable/c/1cdf0d304d820fb13bf0faf532c3459600f9ea43"},{"type":"WEB","url":"https://git.kernel.org/stable/c/210f0f1f67817e7d2348b86b5115a9b85ef5c98b"},{"type":"WEB","url":"https://git.kernel.org/stable/c/4775c3b7a597907e0b97556c7986fda238a377ae"},{"type":"WEB","url":"https://git.kernel.org/stable/c/74995ee8305a7c4d76ee70d6acd996a75eda3c03"},{"type":"WEB","url":"https://git.kernel.org/stable/c/dbe452a905dfe2804647530a9ff3d7e3826ed04d"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98169.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-98169"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"e02789a53d71334b067ad72eee5d4e88a0158083"},{"fixed":"15a221c734b9d044ab769e7e3606b2cab96fb65a"},{"fixed":"74995ee8305a7c4d76ee70d6acd996a75eda3c03"},{"fixed":"210f0f1f67817e7d2348b86b5115a9b85ef5c98b"},{"fixed":"1cdf0d304d820fb13bf0faf532c3459600f9ea43"},{"fixed":"dbe452a905dfe2804647530a9ff3d7e3826ed04d"},{"fixed":"4775c3b7a597907e0b97556c7986fda238a377ae"}]},{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"4.9.125"},{"fixed":"4.10"}]},{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"4.14.68"},{"fixed":"4.15"}]},{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"4.18.6"},{"fixed":"4.19"}]},{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"a94703ff8e3647f8a9a3a92a468450299a7b77e9"}]},{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"82a856f527334ffd69aae26e7dd9e03b19c4a520"}]},{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"25b981bfe192fd208ba04c81f4aa30ffb5141660"}]}],"versions":["v4.9.337","v4.9.336","v4.9.335","v4.9.334","v4.9.333","v4.9.332","v4.9.331","v4.9.330","v4.9.329","v4.9.328","v4.9.327","v4.9.326","v4.9.325","v4.9.324","v4.9.323","v4.9.322","v4.9.321","v4.9.320","v4.9.319","v4.9.318","v4.9.317","v4.9.316","v4.9.315","v4.9.314","v4.9.313","v4.9.312","v4.9.311","v4.9.310","v4.9.309","v4.9.308","v4.9.307","v4.9.306","v4.9.305","v4.9.304","v4.9.303","v4.9.302","v4.9.301","v4.9.300","v4.9.299","v4.9.298","v4.9.297","v4.9.296","v4.9.295","v4.9.294","v4.9.293","v4.9.292","v4.9.291","v4.9.290","v4.9.289","v4.9.288","v4.9.287","v4.9.286","v4.9.285","v4.9.284","v4.9.283","v4.9.282","v4.9.281","v4.9.280","v4.9.279","v4.9.278","v4.9.277","v4.9.276","v4.9.275","v4.9.274","v4.9.273","v4.9.272","v4.9.271","v4.9.270","v4.9.269","v4.9.268","v4.9.267","v4.9.266","v4.9.265","v4.9.264","v4.9.263","v4.9.262","v4.9.261","v4.9.260","v4.9.259","v4.9.258","v4.9.257","v4.9.256","v4.9.255","v4.9.254","v4.9.253","v4.9.252","v4.9.251","v4.9.250","v4.9.249","v4.9.248","v4.9.247","v4.9.246","v4.9.245","v4.9.244","v4.9.243","v4.9.242","v4.9.241","v4.9.240","v4.9.239","v4.9.238","v4.9.237","v4.9.236","v4.9.235","v4.9.234","v4.9.233","v4.9.232","v4.9.231","v4.9.230","v4.9.229","v4.9.228","v4.9.227","v4.9.226","v4.9.225","v4.9.224","v4.9.223","v4.9.222","v4.9.221","v4.9.220","v4.9.219","v4.9.218","v4.9.217","v4.9.216","v4.9.215","v4.9.214","v4.9.213","v4.9.212","v4.9.211","v4.9.210","v4.9.209","v4.9.208","v4.9.207","v4.9.206","v4.9.205","v4.9.204","v4.9.203","v4.9.202","v4.9.201","v4.9.200","v4.9.199","v4.9.198","v4.9.197","v4.9.196","v4.9.195","v4.9.194","v4.9.193","v4.9.192","v4.9.191","v4.9.190","v4.9.189","v4.9.188","v4.9.187","v4.9.186","v4.9.185","v4.9.184","v4.9.183","v4.9.182","v4.9.181","v4.9.180","v4.9.179","v4.9.178","v4.9.177","v4.9.176","v4.9.175","v4.9.174","v4.9.173","v4.9.172","v4.9.171","v4.9.170","v4.9.169","v4.9.168","v4.9.167","v4.9.166","v4.9.165","v4.9.164","v4.9.163","v4.9.162","v4.9.161","v4.9.160","v4.9.159","v4.9.158","v4.9.157","v4.9.156","v4.9.155","v4.9.154","v4.9.153","v4.9.152","v4.9.151","v4.9.150","v4.9.149","v4.9.148","v4.9.147","v4.9.146","v4.9.145","v4.9.144","v4.9.143","v4.9.142","v4.9.141","v4.9.140","v4.9.139","v4.9.138","v4.9.137","v4.9.136","v4.9.135","v4.9.134","v4.9.133","v4.9.132","v4.9.131","v4.9.130","v4.9.129","v4.9.128","v4.9.127","v4.9.126","v4.9.125","v4.14.336","v4.14.335","v4.14.334","v4.14.333","v4.14.332","v4.14.331","v4.14.330","v4.14.329","v4.14.328","v4.14.327","v4.14.326","v4.14.325","v4.14.324","v4.14.323","v4.14.322","v4.14.321","v4.14.320","v4.14.319","v4.14.318","v4.14.317","v4.14.316","v4.14.315","v4.14.314","v4.14.313","v4.14.312","v4.14.311","v4.14.310","v4.14.309","v4.14.308","v4.14.307","v4.14.306","v4.14.305","v4.14.304","v4.14.303","v4.14.302","v4.14.301","v4.14.300","v4.14.299","v4.14.298","v4.14.297","v4.14.296","v4.14.295","v4.14.294","v4.14.293","v4.14.292","v4.14.291","v4.14.290","v4.14.289","v4.14.288","v4.14.287","v4.14.286","v4.14.285","v4.14.284","v4.14.283","v4.14.282","v4.14.281","v4.14.280","v4.14.279","v4.14.278","v4.14.277","v4.14.276","v4.14.275","v4.14.274","v4.14.273","v4.14.272","v4.14.271","v4.14.270","v4.14.269","v4.14.268","v4.14.267","v4.14.266","v4.14.265","v4.14.264","v4.14.263","v4.14.262","v4.14.261","v4.14.260","v4.14.259","v4.14.258","v4.14.257","v4.14.256","v4.14.255","v4.14.254","v4.14.253","v4.14.252","v4.14.251","v4.14.250","v4.14.249","v4.14.248","v4.14.247","v4.14.246","v4.14.245","v4.14.244","v4.14.243","v4.14.242","v4.14.241","v4.14.240","v4.14.239","v4.14.238","v4.14.237","v4.14.236","v4.14.235","v4.14.234","v4.14.233","v4.14.232","v4.14.231","v4.14.230","v4.14.229","v4.14.228","v4.14.227","v4.14.226","v4.14.225","v4.14.224","v4.14.223","v4.14.222","v4.14.221","v4.14.220","v4.14.219","v4.14.218","v4.14.217","v4.14.216","v4.14.215","v4.14.214","v4.14.213","v4.14.212","v4.14.211","v4.14.210","v4.14.209","v4.14.208","v4.14.207","v4.14.206","v4.14.205","v4.14.204","v4.14.203","v4.14.202","v4.14.201","v4.14.200","v4.14.199","v4.14.198","v4.14.197","v4.14.196","v4.14.195","v4.14.194","v4.14.193","v4.14.192","v4.14.191","v4.14.190","v4.14.189","v4.14.188","v4.14.187","v4.14.186","v4.14.185","v4.14.184","v4.14.183","v4.14.182","v4.14.181","v4.14.180","v4.14.179","v4.14.178","v4.14.177","v4.14.176","v4.14.175","v4.14.174","v4.14.173","v4.14.172","v4.14.171","v4.14.170","v4.14.169","v4.14.168","v4.14.167","v4.14.166","v4.14.165","v4.14.164","v4.14.163","v4.14.162","v4.14.161","v4.14.160","v4.14.159","v4.14.158","v4.14.157","v4.14.156","v4.14.155","v4.14.154","v4.14.153","v4.14.152","v4.14.151","v4.14.150","v4.14.149","v4.14.148","v4.14.147","v4.14.146","v4.14.145","v4.14.144","v4.14.143","v4.14.142","v4.14.141","v4.14.140","v4.14.139","v4.14.138","v4.14.137","v4.14.136","v4.14.135","v4.14.134","v4.14.133","v4.14.132","v4.14.131","v4.14.130","v4.14.129","v4.14.128","v4.14.127","v4.14.126","v4.14.125","v4.14.124","v4.14.123","v4.14.122","v4.14.121","v4.14.120","v4.14.119","v4.14.118","v4.14.117","v4.14.116","v4.14.115","v4.14.114","v4.14.113","v4.14.112","v4.14.111","v4.14.110","v4.14.109","v4.14.108","v4.14.107","v4.14.106","v4.14.105","v4.14.104","v4.14.103","v4.14.102","v4.14.101","v4.14.100","v4.14.99","v4.14.98","v4.14.97","v4.14.96","v4.14.95","v4.14.94","v4.14.93","v4.14.92","v4.14.91","v4.14.90","v4.14.89","v4.14.88","v4.14.87","v4.14.86","v4.14.85","v4.14.84","v4.14.83","v4.14.82","v4.14.81","v4.14.80","v4.14.79","v4.14.78","v4.14.77","v4.14.76","v4.14.75","v4.14.74","v4.14.73","v4.14.72","v4.14.71","v4.14.70","v4.14.69","v4.14.68","v4.18.20","v4.18.19","v4.18.18","v4.18.17","v4.18.16","v4.18.15","v4.18.14","v4.18.13","v4.18.12","v4.18.11","v4.18.10","v4.18.9","v4.18.8","v4.18.7","v4.18.6"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98169.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.19.0"},{"fixed":"6.1.189"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.2.0"},{"fixed":"6.6.158"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.7.0"},{"fixed":"6.12.112"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.18.54"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"7.2.8"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98169.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H"}]}