In the Linux kernel, the following vulnerability has been resolved: smb/client: fix out-of-bounds read in smb2_compound_op() If a server sends a truncated response but a large OutputBufferLength, and terminates the EA list early, check_wsl_eas() returns success without validating that the entire OutputBufferLength fits within iov_len. Then smb2_compound_op() does: memcpy(idata->wsl.eas,
Linux Kernel 6.x/5.15 LTS
Exploit
CVE-2026-46155
NVD
Refer to CVE-2026-46155 NVD advisory