HIGH
smb SnapshotArray OOB
CVE-2026-98169
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H
KernelScan AI5.3MEDIUM
01Description
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix potential OOB read in smb3_enum_snapshots() If snapshot_array_size is smaller than GMT_TOKEN_SIZE, smb3_enum_snapshots() sets ret_data_len to sizeof(struct smb_snapshot_array) without verifying the actual length of the server's reply. Because SMB2_ioctl() places no lower bound on the server-supplied OutputCount and allocates retbuf to exactly that length, a short reply results in ret_data_len exceeding the size of retbuf. The subsequent copy_to_user() then reads past the end of retbuf, leaking adjacent slab memory to userspace. The subsequent clamp check is ineffective as it only reduces ret_data_len. Fix this by rejecting replies shorter than sizeof(struct smb_snapshot_array) with -EIO. Note that the bound is set to the 12-byte struct size rather than the 16-byte MIN_SNAPSHOT_ARRAY_SIZE defined in MS-SMB2 3.3.5.15.1, because 12 bytes is exactly what copy_to_user() attempts to read.
02KernelScan AI Analysis
Risk summary
A malicious or compromised SMB server can send an abnormally short reply to the snapshot-enumeration ioctl, causing the Linux SMB client kernel code to copy up to 12 bytes past the end of a slab buffer to userspace. This leaks adjacent kernel heap memory to the requesting process. Any device that mounts SMB/CIFS shares and connects to an untrusted or attacker-controlled server is at risk.
Vulnerability analysis
The SMB client's snapshot enumeration logic sets the amount of data to return to the full size of a fixed structure without first confirming that the server's reply actually contains that many bytes. The routine that receives the reply creates a buffer sized to exactly what the server claims to have sent, so a deliberately short reply causes the client to read past the end of that buffer when handing data back to userspace, leaking adjacent kernel heap memory. The fix adds a check that rejects undersized replies before the transfer happens. This is reachable whenever a client connects to a malicious or compromised SMB server and requests volume shadow-copy snapshot information; the attacker acts as the server and needs no privileges on the client beyond an active SMB mount being present.
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| 4.9 | 4.9.125 | 4.10 | 15a221c734b9 |
| 4.14 | 4.14.68 | 4.15 | 74995ee8305a |
| 4.18 | 4.18.6 | 4.19 | 210f0f1f6781 |
| 6.1 | — | 6.1.189 | 1cdf0d304d82 |
| 6.6 | — | 6.6.158 | dbe452a905df |
| 6.12 | — | 6.12.112 | 4775c3b7a597 |
| 6.18 | — | 6.18.54 | — |
| 7.2 | — | 7.2.8 | — |
| mainline | — | 7.3-rc4 | — |