← العودة للجدول
CVE-2026-46155
CVE-2026-46155 — In the Linux kernel, the following vulnerability has been resolved: smb/client:
📅 2026-05-30
🔴 Critical 🔥 No NVD Exploit Linux CVSS 9.1 🎯 EPSS 0.05%

📋 الوصف الكامل

In the Linux kernel, the following vulnerability has been resolved: smb/client: fix out-of-bounds read in smb2_compound_op() If a server sends a truncated response but a large OutputBufferLength, and terminates the EA list early, check_wsl_eas() returns success without validating that the entire OutputBufferLength fits within iov_len. Then smb2_compound_op() does: memcpy(idata->wsl.eas,

💻 الأنظمة المتأثرة

Linux Kernel 6.x/5.15 LTS

⚠️ نوع التهديد

Exploit

🔗 CVE ID

CVE-2026-46155

📡 المصدر

NVD

✅ الحلول والتخفيف

Refer to CVE-2026-46155 NVD advisory

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←