CVE Database
/

CVE-2026-46185

Back to search

CVE-2026-46185

Published: May 28, 2026

Modified: Jun 1, 2026

PUBLISHED

CVSS v3.1

9.1

CRITICAL

Description

In the Linux kernel, the following vulnerability has been resolved: smb/client: fix out-of-bounds read in symlink_data() Since smb2_check_message() returns success without length validation for the symlink error response, in symlink_data() it is possible for iov->iov_len to be smaller than sizeof(struct smb2_err_rsp). If the buffer only contains the base SMB2 header (64 bytes), accessing err->ErrorContextCount (at offset 66) or err->ByteCount later in symlink_data() will cause an out-of-bounds read.

VendorProductVersions

Linux

Linux

affected
76894f3e2f71177747b8b4763fb180e800279585 - < 2be11faf79e49fb8250a181ff0b4d2b2f084af83
affected
76894f3e2f71177747b8b4763fb180e800279585 - < ef6495d4df6e7af8f3de67e65150881c880f696c
affected
76894f3e2f71177747b8b4763fb180e800279585 - < 15dc0a4de743a1aaa7b859b3aea79f08c695396c
affected
76894f3e2f71177747b8b4763fb180e800279585 - < b8c8a704f0bc133deb171f6aeb6f3a684203e212
affected
76894f3e2f71177747b8b4763fb180e800279585 - < b9561402489d41149f63e001a74384863b7b30a6

+3 more versions

Linux

Linux

affected
6.1
unaffected
0 - < 6.1
unaffected
6.1.175 - <= 6.1.*
unaffected
6.6.140 - <= 6.6.*
unaffected
6.12.88 - <= 6.12.*

+3 more versions

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

Attack Vector

Network

Attack Complexity

Low

Privileges Required

None

User Interaction

None

Scope

Unchanged

Confidentiality

High

Integrity

None

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now