Answer in brief
CVE-2026-98170 records a Unknown severity vulnerability in smb: client: fix OOB struct field reads in move_smb2_ea_to_cifs(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=95907fea4fd8ccc736e0a428e52159b4d42b9958 <d3546cecbf81d98bf3b472d341f981eb48c04f47 || >=95907fea4fd8ccc736e0a428e52159b4d42b9958 <34a3942e787b9c59758115bd65fe1ec89d68c7a4 || >=95907fea4fd8ccc736e0a428e52159b4d42b9958 <13efcd37a9b3d6ffa1579c3dda3e29c893ed9bca || >=95907fea4fd8ccc736e0a428e52159b4d42b9958 <eeb5ef6083e1cefa2ef75041b5597ff228b8d7bb | d3546cecbf81d98bf3b472d341f981eb48c04f47, 34a3942e787b9c59758115bd65fe1ec89d68c7a4, 13efcd37a9b3d6ffa1579c3dda3e29c893ed9bca, eeb5ef6083e1cefa2ef75041b5597ff228b8d7bb |
| Linux/Linuxgeneric | 4.14 | Not reported |
Published upstream
Oct 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Oct 6, 2026
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix OOB struct field reads in move_smb2_ea_to_cifs() In move_smb2_ea_to_cifs(), the while (src_size > 0) loop condition is insufficient. It allows iteration to continue even if the remaining src_size is too small to contain a complete smb2_ea_info structure. Consequently, reads of ea_name_length and ea_value_length can occur out-of-bounds. Fix this by ensuring src_size >= sizeof(*src) before attempting to read any structure fields. Additionally, reject any next_entry_offset that is smaller than sizeof(*src) or that would advance the pointer beyond the available buffer. Note that for calls where the server returns a malformed EA list, the error returned to userspace changes from -ENODATA (getxattr) or -ERANGE (listxattr) to -EIO. This correctly signals a server protocol error rather than misleadingly indicating "attribute not present" or "output buffer too small".
Quoted source text, attributed separately from HOL analysis.