CVE-2026-98167: smb: client: fix server->total_read for compound encrypted PDUs
In the Linux kernel, the following vulnerability has been resolved:
smb: client: fix server->totalread for compound encrypted PDUs
In receiveencryptedstandard(), server->totalread is left at the full decrypted frame size when walking sub-PDUs of a compound encrypted frame. As a result, cifshandlestandard() passes this full size to smb2checkmessage(), causing the PDU length guards to incorrectly validate the entire compound frame instead of the current sub-PDU.
This allows truncated non-last sub-PDUs to bypass length validation, leading to out-of-bounds reads in smb2getdataarealen().
Fix this by setting server->totalread to the true length of the current sub-PDU: nextcmd for non-last sub-PDUs, and the remaining pdulength for the last one.
Affected Software
Event History
Frequently Asked Questions
Which systems are exposed to this issue?
Linux systems using the SMB client are exposed when they process compound encrypted SMB PDUs from a server. The affected code is in the client-side receive path.
What must an attacker provide to trigger the vulnerable path?
The client must receive a compound encrypted frame containing a truncated non-last sub-PDU. The incorrect length validation can then allow an out-of-bounds read in smb2_get_data_area_len().