CVE-2026-98168: smb: client: fix reparse buffer bounds in cifs_query_reparse_point()
In the Linux kernel, the following vulnerability has been resolved:
smb: client: fix reparse buffer bounds in cifsqueryreparsepoint()
In cifsqueryreparsepoint(), the start >= end check before casting to struct reparsedatabuffer only ensures the start pointer is within the response. It fails to verify that there is enough space remaining for the fixed 8-byte header of the structure.
If a server provides a DataOffset that leaves less than 8 bytes remaining, the check passes, but subsequent reads of ReparseTag and ReparseDataLength will occur out-of-bounds.
Fix this by ensuring the remaining space is at least the size of the reparsedatabuffer structure before accessing its fields.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
In cifs_query_reparse_point(), verify that the remaining response space is at least 8 bytes before casting to struct reparse_data_buffer * or accessing ReparseTag and ReparseDataLength; reject responses where the start pointer is at or beyond the end or where fewer than 8 bytes remain.
Event History
Frequently Asked Questions
Who can trigger this issue?
A server that supplies a crafted SMB reparse-point response can trigger the out-of-bounds reads in the Linux kernel SMB client. Systems are exposed when they use the affected client code to query reparse points from an SMB server.
What malformed input is required?
The SMB server must provide a DataOffset that points within the response buffer but leaves fewer than 8 bytes remaining. This passes the prior bounds check and causes subsequent reads of the reparse-point header fields outside the response buffer.
What does the fix change?
The fix requires the remaining response-buffer space to be at least the size of the reparse_data_buffer structure before its fields are accessed. This prevents ReparseTag and ReparseDataLength from being read when the fixed header is incomplete.