KernelScan.io

HIGH Introduced in 4.19

smb CompoundPDU UAF

CVE-2026-98171

CVSS 8.8 / 10.0 NVD

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

KernelScan AI9.8CRITICAL

01

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix next_buffer UAF and NextCommand bounds in compound PDUs Fix several related bounds checking and pointer lifecycle issues in receive_encrypted_standard()'s handling of compound encrypted frames: - Clear next_buffer after assigning it to server->bigbuf. A stale next_buffer pointer can lead to a use-after-free on subsequent error paths. - Update pdu_length to the decrypted plaintext size (buf_size). Using the pre-decryption length allows NextCommand to point into stale ciphertext residue. - Reject next_cmd values smaller than MID_HEADER_SIZE(server). - Fix an integer overflow in the upper bound check by verifying pdu_length - next_cmd < MID_HEADER_SIZE(server), ensuring the trailing slice is large enough for a header.

02

Engine v0.7.0

Risk summary

A malicious or man-in-the-middle SMB server can send crafted compound encrypted responses that trigger a use-after-free and out-of-bounds access in the Linux kernel's SMB client. Any system that mounts SMB shares is at risk; the attacker needs no privileges on the client, only control of or influence over the server responses. Successful exploitation can corrupt kernel memory, leading to information disclosure, privilege escalation, or a kernel crash.

Affectedfs/smb/client/smb2ops.c (smb client)

Vulnerability analysis

When the kernel SMB client processes compound encrypted responses from a server, it continues using the pre-decryption buffer length to validate NextCommand offsets, allowing those offsets to point into stale ciphertext residue instead of the decrypted plaintext. A secondary buffer pointer is also not cleared after being handed off to the server's receive buffer, so on a later error path the stale pointer can be dereferenced after the buffer has already been freed. The bounds check on NextCommand values is further insufficient — it does not reject values too small for a valid header and can suffer an integer overflow in the upper-bound comparison, permitting out-of-bounds access into adjacent memory. The fix updates the length to the decrypted plaintext size immediately after decryption, clears the buffer pointer once it has been assigned, and adds rigorous bounds validation that rejects NextCommand offsets too small for a header or too close to the buffer end. The vulnerable path is reached whenever a client processes encrypted compound responses from an SMB server, so any system that mounts SMB shares from untrusted or potentially compromised servers is exposed; no local privileges are required beyond the ability to initiate or use an existing SMB mount.

03

BranchIntroducedFixed inPatch commit
6.14.196.1.18972eaef1f37a3
6.64.196.6.158491e33144dee
6.124.196.12.112874994657970
6.184.196.18.5496c436e4b010
7.24.197.2.8858d5ac22cb8
mainline4.197.3-rc405762c5bc1cf