PT-2026-44278 · Linux+1 · Linux Kernel+1

CVE-2026-46155

·

Published

2026-05-28

·

Updated

2026-07-24

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An out-of-bounds read exists in the smb2 compound op() function. This occurs when a server sends a truncated response with a large OutputBufferLength and terminates the EA list early. In this scenario, the check wsl eas() function returns success without validating that the entire OutputBufferLength fits within iov len. Consequently, the memcpy() function may read beyond the end of the rsp iov allocation, potentially leaking adjacent kernel heap memory.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:36018
ALSA-2026:36541
CVE-2026-46155
OPENSUSE-SU-2026:10954-1
USN-8488-1
USN-8488-2
USN-8489-1
USN-8507-1
USN-8569-1
USN-8603-1

Affected Products

Linux Kernel
Rocky Linux