CVE-2026-46155

CRITICAL EPSS 37.7%
Published May 28, 20261mo ago · Modified Jun 17, 20261w ago
9.1 CVSS 3.1
Critical
Find Similar
Published May 28, 2026 1mo ago
Last Modified Jun 17, 2026 1w ago

Description

In the Linux kernel, the following vulnerability has been resolved: smb/client: fix out-of-bounds read in smb2_compound_op() If a server sends a truncated response but a large OutputBufferLength, and terminates the EA list early, check_wsl_eas() returns success without validating that the entire OutputBufferLength fits within iov_len. Then smb2_compound_op() does: memcpy(idata->wsl.eas, data[0], size[0]); Where size[0] is OutputBufferLength. If iov_len is smaller than size[0], memcpy can read beyond the end of the rsp_iov allocation and leak adjacent kernel heap memory.

CVSS Details

Base Score
9.1
Exploitability
3.9
Impact
5.2
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality High
Integrity None
Availability High

Threat Intelligence

EPSS Exploit Probability
37.7% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Weaknesses 1

CWE-125 Out-of-bounds Read Memory Safety

Affected Products 6

VendorProductVersionRange
linuxlinux_kernel*≥6.6.32  –  <6.6.140
linuxlinux_kernel*≥6.9  –  <6.12.88
linuxlinux_kernel*≥6.13  –  <6.18.30
linuxlinux_kernel*≥6.19  –  <7.0.7
linuxlinux_kernel7.1any
linuxlinux_kernel7.1any

References 5

  • git.kernel.org https://git.kernel.org/stable/c/512d33bc8ea4ea5c19728ee118715f4b1f4d1926
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/8d09328dfda089675e4c049f3f256064a1d1996b
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/9b3af35645ff9cd334edc130249f9a2fb2bea25f
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/a16f70a71be4b5a4eccf39a9bf09b47285f4cb7c
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/dffb44b2e06a2908e249f0f93156fc987eee1d1c
    Patch

Remediation

  • git.kernel.org https://git.kernel.org/stable/c/512d33bc8ea4ea5c19728ee118715f4b1f4d1926
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/8d09328dfda089675e4c049f3f256064a1d1996b
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/9b3af35645ff9cd334edc130249f9a2fb2bea25f
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/a16f70a71be4b5a4eccf39a9bf09b47285f4cb7c
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/dffb44b2e06a2908e249f0f93156fc987eee1d1c
    Patch