CVE-2026-98170: smb: client: fix OOB struct field reads in move_smb2_ea_to_cifs()
In the Linux kernel, the following vulnerability has been resolved:
smb: client: fix OOB struct field reads in movesmb2eatocifs()
In movesmb2eatocifs(), the while (srcsize > 0) loop condition is insufficient. It allows iteration to continue even if the remaining srcsize is too small to contain a complete smb2eainfo structure. Consequently, reads of eanamelength and eavaluelength can occur out-of-bounds.
Fix this by ensuring srcsize >= sizeof(src) before attempting to read any structure fields. Additionally, reject any nextentryoffset that is smaller than sizeof(src) or that would advance the pointer beyond the available buffer.
Note that for calls where the server returns a malformed EA list, the error returned to userspace changes from -ENODATA (getxattr) or -ERANGE (listxattr) to -EIO. This correctly signals a server protocol error rather than misleadingly indicating "attribute not present" or "output buffer too small".
Affected Software
Event History
Frequently Asked Questions
What systems are exposed to this issue?
Linux systems using the kernel SMB client are exposed when they process extended-attribute (EA) lists returned by an SMB server. The affected parsing path is used for EA-related operations such as getxattr and listxattr.
What does an attacker need to exploit it?
An attacker needs to cause the SMB client to receive a malformed EA list from an SMB server. The malformed list must contain truncated EA structures or invalid next_entry_offset values that lead the client to read structure fields beyond the available buffer.
How can I tell whether the fix is present or whether I am encountering this condition?
With the fix, malformed server EA lists are rejected and getxattr or listxattr returns -EIO. Before the fix, the same malformed responses could lead to out-of-bounds reads and may instead have been reported as -ENODATA for getxattr or -ERANGE for listxattr.