CVE-2026-98169 Overview
CVE-2026-98169 is an out-of-bounds read vulnerability in the Linux kernel's SMB client. The flaw resides in the smb3_enum_snapshots() function, which handles enumeration of previous versions (snapshots) exposed by SMB servers. When a malicious or malformed server returns an SMB2 IOCTL response with an OutputCount smaller than sizeof(struct smb_snapshot_array), the client sets ret_data_len without validating the actual reply size. The subsequent copy_to_user() call then reads past the allocated retbuf, exposing adjacent slab memory to userspace.
Critical Impact
A hostile SMB server can leak kernel slab memory contents to a user-space caller requesting snapshot enumeration, enabling information disclosure and potential kernel memory layout reconstruction.
Affected Products
- Linux kernel SMB client (fs/smb/client)
- Multiple stable Linux kernel branches referenced in the patch set
- Systems that mount SMB shares and invoke the snapshot enumeration IOCTL
Discovery Timeline
- 2026-10-06 - CVE-2026-98169 published to NVD
- 2026-10-07 - Last updated in NVD database
Technical Details for CVE-2026-98169
Vulnerability Analysis
The vulnerability occurs in the SMB3 snapshot enumeration path of the Linux kernel's CIFS/SMB client. User-space callers invoke an IOCTL that triggers smb3_enum_snapshots(), which issues an FSCTL_SRV_ENUMERATE_SNAPSHOTS request through SMB2_ioctl(). The server response is placed into a buffer (retbuf) that is allocated to exactly the server-supplied OutputCount length.
When snapshot_array_size is smaller than GMT_TOKEN_SIZE, the function unconditionally sets ret_data_len to sizeof(struct smb_snapshot_array) (12 bytes). No lower bound is enforced on the server's reply length. A subsequent copy_to_user() then copies 12 bytes from retbuf even if the actual allocation is shorter, reading adjacent slab memory and returning it to the caller.
The later clamp against snapshot_array_size is ineffective because it can only shrink ret_data_len, not reject a short reply. This creates an information disclosure primitive controllable by any SMB server the victim connects to.
Root Cause
The root cause is missing input validation of a length field returned by a remote peer. SMB2_ioctl() places no lower bound on OutputCount, and smb3_enum_snapshots() trusts that the server returned at least a full struct smb_snapshot_array. This is a classic Out-of-Bounds Read triggered by server-controlled length semantics.
Attack Vector
Exploitation requires a victim to mount a share from an attacker-controlled or compromised SMB server and then invoke the snapshot enumeration IOCTL (user interaction, as reflected in the CVSS vector UI:R). The malicious server replies to the snapshot enumeration request with an OutputCount smaller than 12 bytes. The kernel then copies 12 bytes starting at the undersized allocation, leaking neighboring slab memory. Repeated enumeration can be used to profile kernel memory layout or exfiltrate sensitive contents from adjacent allocations.
No verified public exploit code is available at the time of publication. The vulnerability mechanics are described in the upstream commit messages linked under the technical references.
Detection Methods for CVE-2026-98169
Indicators of Compromise
- Unexpected SMB mounts to untrusted or unknown servers from managed Linux hosts
- User-space processes issuing FSCTL_SRV_ENUMERATE_SNAPSHOTS IOCTLs against newly mounted shares
- SMB2 IOCTL responses with abnormally small OutputCount values in captured network traffic
- Kernel log entries from cifs or smb modules referencing snapshot enumeration failures
Detection Strategies
- Monitor mount.cifs and mount -t smb3 invocations against servers outside approved allowlists
- Inspect SMB2 IOCTL traffic for FSCTL_SRV_ENUMERATE_SNAPSHOTS responses with OutputCount below 12 bytes
- Correlate kernel version inventory with the stable commits referenced in the fix to identify unpatched hosts
- Flag user-space programs that enumerate previous versions on externally hosted shares
Monitoring Recommendations
- Enable auditd rules on mount syscalls targeting the cifs and smb3 filesystems
- Forward kernel messages from the SMB client subsystem to a centralized log pipeline for review
- Baseline normal snapshot enumeration behavior per host and alert on anomalies
- Track outbound SMB connections to non-corporate IP ranges at the network perimeter
How to Mitigate CVE-2026-98169
Immediate Actions Required
- Apply the upstream Linux kernel patches referenced in the stable commits below as soon as distribution packages are available
- Restrict outbound SMB (TCP/445) traffic from Linux hosts to a vetted list of file servers
- Disable or avoid snapshot enumeration against untrusted SMB shares until patches are deployed
- Inventory all Linux systems mounting SMB shares and prioritize patching for those exposed to third-party servers
Patch Information
The fix rejects server replies shorter than sizeof(struct smb_snapshot_array) (12 bytes) by returning -EIO, rather than relying on the ineffective downstream clamp. The 12-byte bound is intentionally used because that is exactly the amount copy_to_user() reads. Patch commits are available at: 15a221c7, 1cdf0d30, 210f0f1f, 4775c3b7, 74995ee8, and dbe452a9.
Workarounds
- Block or firewall SMB client traffic to untrusted servers at the host and network layers
- Avoid mounting SMB shares from systems or networks outside administrative control
- Refrain from invoking snapshot or previous-version enumeration tooling against third-party shares until patched
- Where feasible, unload or disable the cifs kernel module on hosts that do not require SMB client functionality
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.