CVE-2026-98168: smb: client: fix reparse buffer bounds in cifs_query_reparse_point()

Published Oct 6, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

smb: client: fix reparse buffer bounds in cifsqueryreparsepoint()

In cifsqueryreparsepoint(), the start >= end check before casting to struct reparsedatabuffer only ensures the start pointer is within the response. It fails to verify that there is enough space remaining for the fixed 8-byte header of the structure.

If a server provides a DataOffset that leaves less than 8 bytes remaining, the check passes, but subsequent reads of ReparseTag and ReparseDataLength will occur out-of-bounds.

Fix this by ensuring the remaining space is at least the size of the reparsedatabuffer structure before accessing its fields.

Affected Software

1 affected component
Linux Linux kernel

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Compensating control

    In cifs_query_reparse_point(), verify that the remaining response space is at least 8 bytes before casting to struct reparse_data_buffer * or accessing ReparseTag and ReparseDataLength; reject responses where the start pointer is at or beyond the end or where fewer than 8 bytes remain.

Event History

Oct 6, 2026
CVE Published
via MITRE·08:44 AM
Data Sourced
via MITRE·08:44 AM
Description
Data Sourced
via NVD·09:17 AM
Description
Oct 7, 2026
Data Sourced
via Microsoft·08:10 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can trigger this issue?

A server that supplies a crafted SMB reparse-point response can trigger the out-of-bounds reads in the Linux kernel SMB client. Systems are exposed when they use the affected client code to query reparse points from an SMB server.

2

What malformed input is required?

The SMB server must provide a DataOffset that points within the response buffer but leaves fewer than 8 bytes remaining. This passes the prior bounds check and causes subsequent reads of the reparse-point header fields outside the response buffer.

3

What does the fix change?

The fix requires the remaining response-buffer space to be at least the size of the reparse_data_buffer structure before its fields are accessed. This prevents ReparseTag and ReparseDataLength from being read when the fixed header is incomplete.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203