cbcvebase.
CVE-2026-46155
published 2026-05-28

CVE-2026-46155: In the Linux kernel, the following vulnerability has been resolved: smb/client: fix out-of-bounds read in smb2_compound_op() If a server sends a truncated…

PriorityP345critical9.1CVSS 3.1
AVNACLPRNUINSUCHINAH
EPSS
0.48%
38.1th percentile
In the Linux kernel, the following vulnerability has been resolved: smb/client: fix out-of-bounds read in smb2_compound_op() If a server sends a truncated response but a large OutputBufferLength, and terminates the EA list early, check_wsl_eas() returns success without validating that the entire OutputBufferLength fits within iov_len. Then smb2_compound_op() does: memcpy(idata->wsl.eas, data[0], size[0]); Where size[0] is OutputBufferLength. If iov_len is smaller than size[0], memcpy can read beyond the end of the rsp_iov allocation and leak adjacent kernel heap memory.

Affected

23 ranges
VendorProductVersion rangeFixed in
linuxlinux
linuxlinux>= 6.6.32 < 6.6.1406.6.140
linuxlinux>= 7449d736bbbd160c76b01b8fcdf72f58a8757d4b < dffb44b2e06a2908e249f0f93156fc987eee1d1cdffb44b2e06a2908e249f0f93156fc987eee1d1c
linuxlinux>= ea41367b2a602f602ea6594fc4a310520dcc64f4 < 9b3af35645ff9cd334edc130249f9a2fb2bea25f9b3af35645ff9cd334edc130249f9a2fb2bea25f
linuxlinux>= ea41367b2a602f602ea6594fc4a310520dcc64f4 < 512d33bc8ea4ea5c19728ee118715f4b1f4d1926512d33bc8ea4ea5c19728ee118715f4b1f4d1926
linuxlinux>= ea41367b2a602f602ea6594fc4a310520dcc64f4 < a16f70a71be4b5a4eccf39a9bf09b47285f4cb7ca16f70a71be4b5a4eccf39a9bf09b47285f4cb7c
linuxlinux>= ea41367b2a602f602ea6594fc4a310520dcc64f4 < 8d09328dfda089675e4c049f3f256064a1d1996b8d09328dfda089675e4c049f3f256064a1d1996b
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 6.13 < 6.18.306.18.30
linuxlinux_kernel>= 6.19 < 7.0.77.0.7
linuxlinux_kernel>= 6.6.32 < 6.6.1406.6.140
linuxlinux_kernel>= 6.9 < 6.12.886.12.88
ubuntulinux
ubuntulinux-aws
ubuntulinux-gcp
ubuntulinux-ibm
ubuntulinux-nvidia
ubuntulinux-oem-7.0
ubuntulinux-oracle
ubuntulinux-raspi
ubuntulinux-realtime

CVSS provenance

nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
vendor_ubuntu8.8HIGH
vendor_redhat7.0HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.