Answer in brief
CVE-2026-98167 records a Unknown severity vulnerability in smb: client: fix server->total_read for compound encrypted PDUs. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=b24df3e30cbf48255db866720fb71f14bf9d2f39 <8703539d22fdbc13dd2db090ee199c3a427b8ea0 || >=b24df3e30cbf48255db866720fb71f14bf9d2f39 <e78fc1d240b27349b45a0f1c3e3c2c401d7e230d || >=b24df3e30cbf48255db866720fb71f14bf9d2f39 <a46eb242e9eef3a3897d166748b23303c516e870 || >=b24df3e30cbf48255db866720fb71f14bf9d2f39 <ebb8a075fdc7af3d196a4f158a0e18dbc394c0e3 || >=b24df3e30cbf48255db866720fb71f14bf9d2f39 <282b72f9a7ef31296c48366db4128882999cc048 || >=b24df3e30cbf48255db866720fb71f14bf9d2f39 <f73726b83e4756fdaa099e1bc1143293bd57ad79 | 8703539d22fdbc13dd2db090ee199c3a427b8ea0, e78fc1d240b27349b45a0f1c3e3c2c401d7e230d, a46eb242e9eef3a3897d166748b23303c516e870, ebb8a075fdc7af3d196a4f158a0e18dbc394c0e3, 282b72f9a7ef31296c48366db4128882999cc048, f73726b83e4756fdaa099e1bc1143293bd57ad79 |
| Linux/Linuxgeneric | 4.19 | Not reported |
Published upstream
Oct 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Oct 6, 2026
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix server->total_read for compound encrypted PDUs In receive_encrypted_standard(), server->total_read is left at the full decrypted frame size when walking sub-PDUs of a compound encrypted frame. As a result, cifs_handle_standard() passes this full size to smb2_check_message(), causing the PDU length guards to incorrectly validate the entire compound frame instead of the current sub-PDU. This allows truncated non-last sub-PDUs to bypass length validation, leading to out-of-bounds reads in smb2_get_data_area_len(). Fix this by setting server->total_read to the true length of the current sub-PDU: next_cmd for non-last sub-PDUs, and the remaining pdu_length for the last one.
Quoted source text, attributed separately from HOL analysis.