CVE Database
/

CVE-2026-23282

Back to search

CVE-2026-23282

Published: Mar 25, 2026

Modified: May 11, 2026

PUBLISHED

Description

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix oops due to uninitialised var in smb2_unlink() If SMB2_open_init() or SMB2_close_init() fails (e.g. reconnect), the iovs set @rqst will be left uninitialised, hence calling SMB2_open_free(), SMB2_close_free() or smb2_set_related() on them will oops. Fix this by initialising @close_iov and @open_iov before setting them in @rqst.

VendorProductVersions

Linux

Linux

affected
1cf9f2a6a544288516a7b9e883a48eba6246bcf2 - < 86163b98891aa9800f6103252e5acc7bb98afb91
affected
1cf9f2a6a544288516a7b9e883a48eba6246bcf2 - < dc710c87af3341554d02d634ada1d2036c49a94a
affected
1cf9f2a6a544288516a7b9e883a48eba6246bcf2 - < 048efe129a297256d3c2088cf8d79515ff5ec864

Linux

Linux

affected
6.17
unaffected
0 - < 6.17
unaffected
6.18.17 - <= 6.18.*
unaffected
6.19.7 - <= 6.19.*
unaffected
7.0 - <= *

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now