{
  "affected": [
    {
      "ranges": [
        {
          "events": [
            {
              "introduced": "e02789a53d71334b067ad72eee5d4e88a0158083"
            },
            {
              "fixed": "15a221c734b9d044ab769e7e3606b2cab96fb65a"
            },
            {
              "fixed": "74995ee8305a7c4d76ee70d6acd996a75eda3c03"
            },
            {
              "fixed": "210f0f1f67817e7d2348b86b5115a9b85ef5c98b"
            },
            {
              "fixed": "1cdf0d304d820fb13bf0faf532c3459600f9ea43"
            },
            {
              "fixed": "dbe452a905dfe2804647530a9ff3d7e3826ed04d"
            },
            {
              "fixed": "4775c3b7a597907e0b97556c7986fda238a377ae"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        },
        {
          "events": [
            {
              "introduced": "4.9.125"
            },
            {
              "fixed": "4.10"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        },
        {
          "events": [
            {
              "introduced": "4.14.68"
            },
            {
              "fixed": "4.15"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        },
        {
          "events": [
            {
              "introduced": "4.18.6"
            },
            {
              "fixed": "4.19"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        },
        {
          "events": [
            {
              "introduced": "a94703ff8e3647f8a9a3a92a468450299a7b77e9"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        },
        {
          "events": [
            {
              "introduced": "82a856f527334ffd69aae26e7dd9e03b19c4a520"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        },
        {
          "events": [
            {
              "introduced": "25b981bfe192fd208ba04c81f4aa30ffb5141660"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        }
      ]
    },
    {
      "package": {
        "ecosystem": "Linux",
        "name": "Kernel"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "4.19.0"
            },
            {
              "fixed": "6.1.189"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.2.0"
            },
            {
              "fixed": "6.6.158"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.7.0"
            },
            {
              "fixed": "6.12.112"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.13.0"
            },
            {
              "fixed": "6.18.54"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.19.0"
            },
            {
              "fixed": "7.2.8"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "database_specific": {
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98169.json"
  },
  "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: fix potential OOB read in smb3_enum_snapshots()\n\nIf snapshot_array_size is smaller than GMT_TOKEN_SIZE,\nsmb3_enum_snapshots() sets ret_data_len to\nsizeof(struct smb_snapshot_array) without verifying the actual length\nof the server's reply.\n\nBecause SMB2_ioctl() places no lower bound on the server-supplied\nOutputCount and allocates retbuf to exactly that length, a short reply\nresults in ret_data_len exceeding the size of retbuf. The subsequent\ncopy_to_user() then reads past the end of retbuf, leaking adjacent slab\nmemory to userspace.  The subsequent clamp check is ineffective as it\nonly reduces ret_data_len.\n\nFix this by rejecting replies shorter than\nsizeof(struct smb_snapshot_array) with -EIO. Note that the bound is set\nto the 12-byte struct size rather than the 16-byte\nMIN_SNAPSHOT_ARRAY_SIZE defined in MS-SMB2 3.3.5.15.1, because 12 bytes\nis exactly what copy_to_user() attempts to read.",
  "id": "CVE-2026-98169",
  "modified": "2026-10-08T02:30:43.445560384Z",
  "published": "2026-10-06T08:44:14.339Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/15a221c734b9d044ab769e7e3606b2cab96fb65a"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/1cdf0d304d820fb13bf0faf532c3459600f9ea43"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/210f0f1f67817e7d2348b86b5115a9b85ef5c98b"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/4775c3b7a597907e0b97556c7986fda238a377ae"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/74995ee8305a7c4d76ee70d6acd996a75eda3c03"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/dbe452a905dfe2804647530a9ff3d7e3826ed04d"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98169.json"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-98169"
    },
    {
      "type": "PACKAGE",
      "url": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"
    }
  ],
  "schema_version": "1.9.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H",
      "type": "CVSS_V3"
    }
  ],
  "summary": "smb: client: fix potential OOB read in smb3_enum_snapshots()"
}