Sceawere

Vulnerability Detail

CVE-2026-98318UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Linux Kernel SMB Symlink Buffer Overflow

Vulnerability Metadata

Severity
High
Score / CVSS
7.8
Creation Date
1d ago
Vendor
Linux
Product
Linux
Attack Type
N/A
Vector String
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

In the Linux kernel, the following vulnerability has been resolved: smb: client: validate absolute native symlink targets before NT fixups With symlinkroot unset, an absolute target is copied without conversion to an NT drive path. Later code still assumes an NT prefix is present when modifying the target and calculating the print name length. For "/ab", this causes two failures: sym[5] and path[5] are written past their allocations, and plen -= 2 * poff subtracts an assumed 8-byte prefix from a 6-byte UTF-16 target, wrapping u16 plen to 65534. That underflow causes another overflow: memcpy() copies 65534 bytes into a 24-byte buffer. A user with write access to a mounted share can trigger these bugs with default settings. Validate the NT drive prefix, including an ASCII drive letter, before accessing fixed offsets or subtracting the prefix length.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.8",
  "pubDate": "2026-10-06T09:18:23.670Z",
  "pubdate": "2026-10-06T09:18:23.670Z",
  "executiveSummary": "A critical memory corruption vulnerability exists in the Linux kernel SMB client implementation related to the processing of absolute native symlink targets.\nThe vulnerability is characterized by improper validation of symlink target paths when the symlinkroot configuration is unset, leading to out-of-bounds memory writes and integer underflow conditions.\nAffected systems include Linux kernel environments utilizing the SMB client with mounted shares. A local attacker with write access to a mounted share can trigger these flaws to execute arbitrary memory writes.\nThe impact includes potential system crashes, denial-of-service, or the potential for arbitrary code execution if the memory corruption is successfully weaponized to overwrite sensitive kernel structures.\nExploitation requires the attacker to have legitimate write access to a mounted SMB share, which allows them to manipulate symlink target strings, causing the kernel to process malformed paths that bypass bounds checking.\nThis vulnerability highlights a flaw in how the SMB client assumes the structure of incoming symlink metadata, specifically failing to account for the absence of expected NT drive prefixes before applying transformation logic.",
  "technicalDetails": "The root cause of this vulnerability lies in the Linux kernel SMB client's handling of absolute native symlink targets. When the symlinkroot configuration is not explicitly set, the client logic fails to convert absolute paths into valid NT drive paths before performing subsequent modifications.\nThe kernel's SMB client logic assumes that every absolute symlink target will contain a mandatory NT drive prefix (e.g., a drive letter structure). When an attacker provides a target such as '/ab', the client lacks the necessary checks to identify that the expected prefix is missing.\nThis triggers a severe out-of-bounds write: the internal buffers 'sym' and 'path' are written past their allocated boundaries because the logic incorrectly calculates the required buffer space based on the assumption of a longer prefix.\nFurthermore, an integer underflow occurs during the calculation of the print name length ('plen'). The code attempts to subtract the assumed 8-byte NT prefix length from a significantly shorter 6-byte UTF-16 target string. This subtraction causes the unsigned 16-bit 'plen' variable to underflow, wrapping its value to 65534.\nThis underflow directly facilitates a secondary, larger buffer overflow. The subsequent 'memcpy()' operation uses the corrupted 'plen' value (65534) to copy data into a significantly smaller destination buffer of only 24 bytes, resulting in a linear heap-based buffer overflow.\nThe attack flow proceeds as follows: 1) An attacker with write access to a mounted SMB share creates a symlink with a specifically crafted absolute target path that lacks a valid NT prefix. 2) The SMB client attempts to process this symlink metadata during directory traversal or file access. 3) The kernel encounters the malformed path, failing to validate the prefix structure. 4) The underflow of the 'plen' variable occurs, triggering the oversized 'memcpy()'. 5) The resulting memory corruption crashes the kernel or allows for the overwrite of adjacent kernel memory structures, leading to a system-wide compromise."
}
CVE-2026-98318: Linux Kernel SMB Symlink Buffer Overflow (HIGH Severity, CVSS: 7.8) | Sceawere