Sceawere

Vulnerability Detail

CVE-2026-98171UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Linux Kernel SMB UAF Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
8.8
Creation Date
1d ago
Vendor
Linux
Product
Linux
Attack Type
N/A
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix next_buffer UAF and NextCommand bounds in compound PDUs Fix several related bounds checking and pointer lifecycle issues in receive_encrypted_standard()'s handling of compound encrypted frames: - Clear next_buffer after assigning it to server->bigbuf. A stale next_buffer pointer can lead to a use-after-free on subsequent error paths. - Update pdu_length to the decrypted plaintext size (buf_size). Using the pre-decryption length allows NextCommand to point into stale ciphertext residue. - Reject next_cmd values smaller than MID_HEADER_SIZE(server). - Fix an integer overflow in the upper bound check by verifying pdu_length - next_cmd < MID_HEADER_SIZE(server), ensuring the trailing slice is large enough for a header.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.8",
  "pubDate": "2026-10-06T09:17:58.773Z",
  "pubdate": "2026-10-06T09:17:58.773Z",
  "executiveSummary": "This vulnerability involves multiple memory safety and boundary checking defects within the Linux kernel's SMB client implementation, specifically in the receive_encrypted_standard() function.\nThe primary security risks include a Use-After-Free (UAF) condition and potential out-of-bounds memory access triggered by malformed compound encrypted PDU (Protocol Data Unit) handling.\nThe flaw allows an attacker capable of sending crafted SMB traffic to trigger memory corruption, which could lead to kernel panics, denial-of-service (DoS), or potentially arbitrary code execution depending on the system's memory layout and state.\nThe vulnerability resides in how the client processes encrypted frames, specifically failing to manage the lifecycle of the next_buffer pointer and improperly validating the bounds of NextCommand headers.\nSuccessful exploitation requires the ability to reach the SMB client's decryption logic, typically through a malicious or compromised SMB server. No specific privilege elevation is required if an attacker can force the client to connect to a malicious endpoint.",
  "technicalDetails": "The vulnerability originates in the receive_encrypted_standard() function of the Linux kernel's SMB client, which handles the decryption and parsing of compound encrypted PDUs. The implementation suffered from three distinct but related flaws: improper pointer lifecycle management, incorrect length validation for encrypted payloads, and insufficient bounds checking on command headers.\nThe Use-After-Free (UAF) condition is triggered by the failure to clear the next_buffer pointer after it is assigned to server->bigbuf. Because the pointer remains in a stale state, subsequent error handling routines may attempt to access or free this memory again after it has been reassigned or released, leading to memory corruption.\nFurthermore, the function failed to update the pdu_length to the decrypted plaintext size (buf_size), instead retaining the pre-decryption length. This discrepancy allows the NextCommand pointer to reference stale ciphertext residue outside the bounds of the actual decrypted command structure.\nThe bounds checking logic for the NextCommand field was also insufficient. The code failed to reject next_cmd values that were smaller than the required MID_HEADER_SIZE(server). Additionally, an integer overflow in the upper-bound validation logic allowed for unsafe pointer arithmetic: by evaluating pdu_length - next_cmd, the kernel failed to ensure that the trailing slice of the buffer was of sufficient size to contain a valid header. This allows for an out-of-bounds read or write if an attacker provides a crafted PDU that tricks the client into reading beyond the valid decrypted buffer.\nThe attack flow involves an attacker acting as a malicious SMB server sending a series of compound encrypted frames to a Linux SMB client. By crafting the NextCommand offsets and the overall PDU length, the attacker manipulates the client into processing memory buffers that exceed the allocated plaintext size. This triggers the memory safety violation, potentially allowing the attacker to influence kernel memory state or cause a system crash. The lack of validation on the next_cmd size ensures that even malformed packets with non-standard header offsets can successfully bypass initial sanity checks, facilitating the exploitation of the downstream memory management bugs."
}
CVE-2026-98171: Linux Kernel SMB UAF Vulnerability (HIGH Severity, CVSS: 8.8) | Sceawere