Junglewise Threat Intelligence

CVE-2026-46185: Linux kernel SMB client out-of-bounds read in symlink_data

CVE-2026-46185 · Severity: info · CVSS 4.3 · Published 2026-05-28

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's SMB client could allow a malicious server to trigger an out-of-bounds memory read. This component is responsible for connecting to network file shares (like Windows or Samba drives). An exploit could lead to system instability or the exposure of small amounts of kernel memory when the system attempts to process a specially crafted symbolic link response.

Technical details

An out-of-bounds read vulnerability exists in the Linux kernel SMB client (CIFS/SMB2+) within the symlink_data() function. The root cause is that smb2_check_message() returns success for symlink error responses without performing adequate length validation. If a malicious or malformed SMB2 response contains only the 64-byte base header but indicates a symlink error, subsequent code in symlink_data() attempts to access fields like ErrorContextCount (offset 66) or ByteCount, which reside beyond the actual buffer length. This can be triggered by a network-adjacent or remote SMB server. Patches have been released for various stable kernel branches (e.g., 6.x, 5.x) to ensure length validation is performed before processing these responses.

Affected products

  • Linux Linux kernel All versions prior to the May 2026 patches

Timeline

  • 2026-05-02: other: Vulnerability reported by Zisen Ye
  • 2026-05-14: patched: Patches committed to various stable kernel trees
  • 2026-05-28: disclosed: CVE published in NVD dataset

References