CVE-2026-98171: smb: client: fix next_buffer UAF and NextCommand bounds in compound PDUs
In the Linux kernel, the following vulnerability has been resolved:
smb: client: fix nextbuffer UAF and NextCommand bounds in compound PDUs
Fix several related bounds checking and pointer lifecycle issues in receiveencryptedstandard()'s handling of compound encrypted frames:
- Clear nextbuffer after assigning it to server->bigbuf. A stale nextbuffer pointer can lead to a use-after-free on subsequent error paths. - Update pdulength to the decrypted plaintext size (bufsize). Using the pre-decryption length allows NextCommand to point into stale ciphertext residue. - Reject nextcmd values smaller than MIDHEADERSIZE(server). - Fix an integer overflow in the upper bound check by verifying pdulength - nextcmd < MIDHEADERSIZE(server), ensuring the trailing slice is large enough for a header.