CVE 9.1 CRITICAL

smb/client: fix out-of-bounds read in symlink_data()_CVE-2026-46185

9.1 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

Description

In the Linux kernel, the following vulnerability has been resolved:

smb/client: fix out-of-bounds read in symlink_data()

Since smb2_check_message() returns success without length validation for
the symlink error response, in symlink_data() it is possible for
iov->iov_len to be smaller than sizeof(struct smb2_err_rsp). If the buffer
only contains the base SMB2 header (64 bytes), accessing
err->ErrorContextCount (at offset 66) or err->ByteCount later in
symlink_data() will cause an out-of-bounds read.

Basic Information

ID CVE-2026-46185
Source Linux
Published May 28, 2026 at 09:36
Modified May 30, 2026 at 10:48

Affected Product

Vendor Linux
Product Linux
Version 76894f3e2f71177747b8b4763fb180e800279585
Affected Versions Linux Linux 76894f3e2f71177747b8b4763fb180e800279585
Linux Linux 76894f3e2f71177747b8b4763fb180e800279585
Linux Linux 76894f3e2f71177747b8b4763fb180e800279585
Linux Linux 76894f3e2f71177747b8b4763fb180e800279585
Linux Linux 76894f3e2f71177747b8b4763fb180e800279585
Linux Linux 2d046892a493d9760c35fdaefc3017f27f91b621
Linux Linux 6.0.16
Linux Linux 6.1

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.