CVE-2026-46155
CRITICAL EPSS 37.7%
Published May 28, 20261mo ago · Modified Jun 17, 20261w ago
9.1 CVSS 3.1
Published May 28, 2026 1mo ago
Last Modified Jun 17, 2026 1w ago
Description
In the Linux kernel, the following vulnerability has been resolved: smb/client: fix out-of-bounds read in smb2_compound_op() If a server sends a truncated response but a large OutputBufferLength, and terminates the EA list early, check_wsl_eas() returns success without validating that the entire OutputBufferLength fits within iov_len. Then smb2_compound_op() does: memcpy(idata->wsl.eas, data[0], size[0]); Where size[0] is OutputBufferLength. If iov_len is smaller than size[0], memcpy can read beyond the end of the rsp_iov allocation and leak adjacent kernel heap memory.
CVSS Details
Base Score
Exploitability
Impact
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality High
Integrity None
Availability High
Threat Intelligence
EPSS Exploit Probability
37.7% percentile
Exploit & Patch Status
No Known Exploit
Patch Available
Weaknesses 1
CWE-125 Out-of-bounds Read Memory Safety
Affected Products 6
References 5
- git.kernel.org https://git.kernel.org/stable/c/512d33bc8ea4ea5c19728ee118715f4b1f4d1926
- git.kernel.org https://git.kernel.org/stable/c/8d09328dfda089675e4c049f3f256064a1d1996b
- git.kernel.org https://git.kernel.org/stable/c/9b3af35645ff9cd334edc130249f9a2fb2bea25f
- git.kernel.org https://git.kernel.org/stable/c/a16f70a71be4b5a4eccf39a9bf09b47285f4cb7c
- git.kernel.org https://git.kernel.org/stable/c/dffb44b2e06a2908e249f0f93156fc987eee1d1c
Remediation
- git.kernel.org https://git.kernel.org/stable/c/512d33bc8ea4ea5c19728ee118715f4b1f4d1926
- git.kernel.org https://git.kernel.org/stable/c/8d09328dfda089675e4c049f3f256064a1d1996b
- git.kernel.org https://git.kernel.org/stable/c/9b3af35645ff9cd334edc130249f9a2fb2bea25f
- git.kernel.org https://git.kernel.org/stable/c/a16f70a71be4b5a4eccf39a9bf09b47285f4cb7c
- git.kernel.org https://git.kernel.org/stable/c/dffb44b2e06a2908e249f0f93156fc987eee1d1c