CVE-2026-46185
Published: May 28, 2026
Modified: Jun 1, 2026
CVSS v3.1
9.1
Description
In the Linux kernel, the following vulnerability has been resolved: smb/client: fix out-of-bounds read in symlink_data() Since smb2_check_message() returns success without length validation for the symlink error response, in symlink_data() it is possible for iov->iov_len to be smaller than sizeof(struct smb2_err_rsp). If the buffer only contains the base SMB2 header (64 bytes), accessing err->ErrorContextCount (at offset 66) or err->ByteCount later in symlink_data() will cause an out-of-bounds read.
| Vendor | Product | Versions |
|---|---|---|
Linux | Linux | affected 76894f3e2f71177747b8b4763fb180e800279585 - < 2be11faf79e49fb8250a181ff0b4d2b2f084af83affected 76894f3e2f71177747b8b4763fb180e800279585 - < ef6495d4df6e7af8f3de67e65150881c880f696caffected 76894f3e2f71177747b8b4763fb180e800279585 - < 15dc0a4de743a1aaa7b859b3aea79f08c695396caffected 76894f3e2f71177747b8b4763fb180e800279585 - < b8c8a704f0bc133deb171f6aeb6f3a684203e212affected 76894f3e2f71177747b8b4763fb180e800279585 - < b9561402489d41149f63e001a74384863b7b30a6+3 more versions |
Linux | Linux | affected 6.1unaffected 0 - < 6.1unaffected 6.1.175 - <= 6.1.*unaffected 6.6.140 - <= 6.6.*unaffected 6.12.88 - <= 6.12.*+3 more versions |
CVSS v3.1 Details
CVSS v3.1 Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now