CVE-2026-98170: smb: client: fix OOB struct field reads in move_smb2_ea_to_cifs()

Published Oct 6, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

smb: client: fix OOB struct field reads in movesmb2eatocifs()

In movesmb2eatocifs(), the while (srcsize > 0) loop condition is insufficient. It allows iteration to continue even if the remaining srcsize is too small to contain a complete smb2eainfo structure. Consequently, reads of eanamelength and eavaluelength can occur out-of-bounds.

Fix this by ensuring srcsize >= sizeof(src) before attempting to read any structure fields. Additionally, reject any nextentryoffset that is smaller than sizeof(src) or that would advance the pointer beyond the available buffer.

Note that for calls where the server returns a malformed EA list, the error returned to userspace changes from -ENODATA (getxattr) or -ERANGE (listxattr) to -EIO. This correctly signals a server protocol error rather than misleadingly indicating "attribute not present" or "output buffer too small".

Affected Software

1 affected component
Linux Linux kernel

Event History

Oct 6, 2026
CVE Published
via MITRE·08:44 AM
Data Sourced
via MITRE·08:44 AM
Description
Data Sourced
via NVD·09:17 AM
Description
Oct 7, 2026
Data Sourced
via Microsoft·08:04 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What systems are exposed to this issue?

Linux systems using the kernel SMB client are exposed when they process extended-attribute (EA) lists returned by an SMB server. The affected parsing path is used for EA-related operations such as getxattr and listxattr.

2

What does an attacker need to exploit it?

An attacker needs to cause the SMB client to receive a malformed EA list from an SMB server. The malformed list must contain truncated EA structures or invalid next_entry_offset values that lead the client to read structure fields beyond the available buffer.

3

How can I tell whether the fix is present or whether I am encountering this condition?

With the fix, malformed server EA lists are rejected and getxattr or listxattr returns -EIO. Before the fix, the same malformed responses could lead to out-of-bounds reads and may instead have been reported as -ENODATA for getxattr or -ERANGE for listxattr.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203