CVE-2026-46155
Published: May 28, 2026
Modified: May 30, 2026
CVSS v3.1
9.1
Description
In the Linux kernel, the following vulnerability has been resolved: smb/client: fix out-of-bounds read in smb2_compound_op() If a server sends a truncated response but a large OutputBufferLength, and terminates the EA list early, check_wsl_eas() returns success without validating that the entire OutputBufferLength fits within iov_len. Then smb2_compound_op() does: memcpy(idata->wsl.eas, data[0], size[0]); Where size[0] is OutputBufferLength. If iov_len is smaller than size[0], memcpy can read beyond the end of the rsp_iov allocation and leak adjacent kernel heap memory.
| Vendor | Product | Versions |
|---|---|---|
Linux | Linux | affected 7449d736bbbd160c76b01b8fcdf72f58a8757d4b - < dffb44b2e06a2908e249f0f93156fc987eee1d1caffected ea41367b2a602f602ea6594fc4a310520dcc64f4 - < 9b3af35645ff9cd334edc130249f9a2fb2bea25faffected ea41367b2a602f602ea6594fc4a310520dcc64f4 - < 512d33bc8ea4ea5c19728ee118715f4b1f4d1926affected ea41367b2a602f602ea6594fc4a310520dcc64f4 - < a16f70a71be4b5a4eccf39a9bf09b47285f4cb7caffected ea41367b2a602f602ea6594fc4a310520dcc64f4 - < 8d09328dfda089675e4c049f3f256064a1d1996b+1 more versions |
Linux | Linux | affected 6.9unaffected 0 - < 6.9unaffected 6.6.140 - <= 6.6.*unaffected 6.12.88 - <= 6.12.*unaffected 6.18.30 - <= 6.18.*+2 more versions |
CVSS v3.1 Details
CVSS v3.1 Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now