CVE-2026-46155 (GCVE-0-2026-46155)
Vulnerability from cvelistv5
Published
2026-05-28 09:36
Modified
2026-08-05 12:30
Severity ?
Summary
In the Linux kernel, the following vulnerability has been resolved: smb/client: fix out-of-bounds read in smb2_compound_op() If a server sends a truncated response but a large OutputBufferLength, and terminates the EA list early, check_wsl_eas() returns success without validating that the entire OutputBufferLength fits within iov_len. Then smb2_compound_op() does: memcpy(idata->wsl.eas, data[0], size[0]); Where size[0] is OutputBufferLength. If iov_len is smaller than size[0], memcpy can read beyond the end of the rsp_iov allocation and leak adjacent kernel heap memory.
Impacted products
Vendor Product Version
Linux Linux Version: 7449d736bbbd160c76b01b8fcdf72f58a8757d4b
Version: ea41367b2a602f602ea6594fc4a310520dcc64f4
Version: ea41367b2a602f602ea6594fc4a310520dcc64f4
Version: ea41367b2a602f602ea6594fc4a310520dcc64f4
Version: ea41367b2a602f602ea6594fc4a310520dcc64f4
Version: 6.6.32   
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "fs/smb/client/smb2inode.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "dffb44b2e06a2908e249f0f93156fc987eee1d1c",
              "status": "affected",
              "version": "7449d736bbbd160c76b01b8fcdf72f58a8757d4b",
              "versionType": "git"
            },
            {
              "lessThan": "9b3af35645ff9cd334edc130249f9a2fb2bea25f",
              "status": "affected",
              "version": "ea41367b2a602f602ea6594fc4a310520dcc64f4",
              "versionType": "git"
            },
            {
              "lessThan": "512d33bc8ea4ea5c19728ee118715f4b1f4d1926",
              "status": "affected",
              "version": "ea41367b2a602f602ea6594fc4a310520dcc64f4",
              "versionType": "git"
            },
            {
              "lessThan": "a16f70a71be4b5a4eccf39a9bf09b47285f4cb7c",
              "status": "affected",
              "version": "ea41367b2a602f602ea6594fc4a310520dcc64f4",
              "versionType": "git"
            },
            {
              "lessThan": "8d09328dfda089675e4c049f3f256064a1d1996b",
              "status": "affected",
              "version": "ea41367b2a602f602ea6594fc4a310520dcc64f4",
              "versionType": "git"
            },
            {
              "lessThan": "6.6.140",
              "status": "affected",
              "version": "6.6.32",
              "versionType": "semver"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "fs/smb/client/smb2inode.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.9"
            },
            {
              "lessThan": "6.9",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.140",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.12.*",
              "status": "unaffected",
              "version": "6.12.88",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.18.*",
              "status": "unaffected",
              "version": "6.18.30",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "7.0.*",
              "status": "unaffected",
              "version": "7.0.7",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "7.1",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.140",
                  "versionStartIncluding": "6.6.32",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.12.88",
                  "versionStartIncluding": "6.9",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.18.30",
                  "versionStartIncluding": "6.9",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.0.7",
                  "versionStartIncluding": "6.9",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.1",
                  "versionStartIncluding": "6.9",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmb/client: fix out-of-bounds read in smb2_compound_op()\n\nIf a server sends a truncated response but a large OutputBufferLength, and\nterminates the EA list early, check_wsl_eas() returns success without\nvalidating that the entire OutputBufferLength fits within iov_len.\n\nThen smb2_compound_op() does:\n    memcpy(idata-\u003ewsl.eas, data[0], size[0]);\n\nWhere size[0] is OutputBufferLength. If iov_len is smaller than size[0],\nmemcpy can read beyond the end of the rsp_iov allocation and leak adjacent\nkernel heap memory."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 9.1,
            "baseSeverity": "CRITICAL",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:N - The bug is in the in-kernel SMB client processing a response from a remote SMB server over TCP/445; the out-of-bounds read is driven entirely by attacker-controlled data received from a remote peer.\nAC:L - A malicious server reliably and deterministically crafts the triggering response (truncated payload with a large OutputBufferLength and early-terminated EA list); there is no race or uncontrolled memory-layout condition required to cause the OOB read.\nPR:N - The attacker is the remote SMB server (or a network MITM) and needs no privileges or account on the victim client system to send the malicious response.\nUI:N - On an already-mounted share served by a compromised/malicious server or via MITM, the vulnerable WSL-EA query fires during routine stat/readdir on reparse-point files with no deliberate victim action, consistent with the sibling CVE-2026-46185.\nS:U - The leak is confined to the kernel\u0027s own security authority and exposed to local processes; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - The memcpy reads adjacent kernel heap memory (up to tens of bytes) into wsl.eas, and crafted EA value fields cause that leaked kernel data to be reflected to userspace as the file\u0027s uid/gid/mode/device via stat().\nI:N - The flaw is a pure out-of-bounds read; the destination buffer is size-bounded (outlen \u2264 MAX) so no kernel memory is written or corrupted, providing no integrity/write primitive.\nA:H - The out-of-bounds read can cross into an unmapped page (and traps under KASAN), producing a kernel oops/panic and denial of service."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T12:30:06.776Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/dffb44b2e06a2908e249f0f93156fc987eee1d1c"
        },
        {
          "url": "https://git.kernel.org/stable/c/9b3af35645ff9cd334edc130249f9a2fb2bea25f"
        },
        {
          "url": "https://git.kernel.org/stable/c/512d33bc8ea4ea5c19728ee118715f4b1f4d1926"
        },
        {
          "url": "https://git.kernel.org/stable/c/a16f70a71be4b5a4eccf39a9bf09b47285f4cb7c"
        },
        {
          "url": "https://git.kernel.org/stable/c/8d09328dfda089675e4c049f3f256064a1d1996b"
        }
      ],
      "title": "smb/client: fix out-of-bounds read in smb2_compound_op()",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2026-46155",
    "datePublished": "2026-05-28T09:36:11.092Z",
    "dateReserved": "2026-05-13T15:03:33.102Z",
    "dateUpdated": "2026-08-05T12:30:06.776Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…