Junglewise Threat Intelligence

CVE-2026-46155: Linux Kernel SMB client out-of-bounds read in smb2_compound_op

CVE-2026-46155 · Severity: info · CVSS 0 · Published 2026-05-28

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's SMB client could allow a malicious or compromised server to read sensitive information from the client's memory. This occurs when the client processes a specially crafted response from a file server. An exploit could lead to the leakage of adjacent kernel memory, potentially exposing credentials or other private data.

Technical details

An out-of-bounds read vulnerability exists in the Linux kernel SMB client (cifs.ko) within the smb2_compound_op() function. The root cause is a failure in check_wsl_eas() to validate that the OutputBufferLength provided by the server fits within the actual allocated buffer (iov_len) when an Extended Attribute (EA) list is terminated early. A malicious server can send a truncated response with a large OutputBufferLength, causing a subsequent memcpy() to read beyond the end of the rsp_iov allocation. This can result in the leakage of adjacent kernel heap memory to the attacker. The issue has been resolved by adding proper bounds checking against the iov_len in the check_wsl_eas() function.

Affected products

  • Linux Linux Kernel Fixed in versions 512d33b, 8d09328, 9b3af35, a16f70a, dffb44b

Timeline

  • 2026-05-06: other: Patch authored
  • 2026-05-28: advisory: CVE published

References