KernelScan.io

HIGH

smb SnapshotArray OOB

CVE-2026-98169

CVSS 7.1 / 10.0 NVD

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H

KernelScan AI5.3MEDIUM

01

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix potential OOB read in smb3_enum_snapshots() If snapshot_array_size is smaller than GMT_TOKEN_SIZE, smb3_enum_snapshots() sets ret_data_len to sizeof(struct smb_snapshot_array) without verifying the actual length of the server's reply. Because SMB2_ioctl() places no lower bound on the server-supplied OutputCount and allocates retbuf to exactly that length, a short reply results in ret_data_len exceeding the size of retbuf. The subsequent copy_to_user() then reads past the end of retbuf, leaking adjacent slab memory to userspace. The subsequent clamp check is ineffective as it only reduces ret_data_len. Fix this by rejecting replies shorter than sizeof(struct smb_snapshot_array) with -EIO. Note that the bound is set to the 12-byte struct size rather than the 16-byte MIN_SNAPSHOT_ARRAY_SIZE defined in MS-SMB2 3.3.5.15.1, because 12 bytes is exactly what copy_to_user() attempts to read.

02

Engine v0.7.0

Risk summary

A malicious or compromised SMB server can send an abnormally short reply to the snapshot-enumeration ioctl, causing the Linux SMB client kernel code to copy up to 12 bytes past the end of a slab buffer to userspace. This leaks adjacent kernel heap memory to the requesting process. Any device that mounts SMB/CIFS shares and connects to an untrusted or attacker-controlled server is at risk.

Affectedfs/smb/client/smb2ops.c (smb client)

Vulnerability analysis

The SMB client's snapshot enumeration logic sets the amount of data to return to the full size of a fixed structure without first confirming that the server's reply actually contains that many bytes. The routine that receives the reply creates a buffer sized to exactly what the server claims to have sent, so a deliberately short reply causes the client to read past the end of that buffer when handing data back to userspace, leaking adjacent kernel heap memory. The fix adds a check that rejects undersized replies before the transfer happens. This is reachable whenever a client connects to a malicious or compromised SMB server and requests volume shadow-copy snapshot information; the attacker acts as the server and needs no privileges on the client beyond an active SMB mount being present.

03

BranchIntroducedFixed inPatch commit
4.94.9.1254.1015a221c734b9
4.144.14.684.1574995ee8305a
4.184.18.64.19210f0f1f6781
6.1—6.1.1891cdf0d304d82
6.6—6.6.158dbe452a905df
6.12—6.12.1124775c3b7a597
6.18—6.18.54—
7.2—7.2.8—
mainline—7.3-rc4—