CVE-2026-89792
7.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Summary
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: prevent out-of-bounds reads in share config responses
Validate IPC share configuration payload sizes before consuming variable-length fields. Bound veto list parsing and account for the separator byte when deriving the path length.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | a677ebd8ca2f2632ccdecbad7b87641274e15aac < 61a8d06600c8c397f9a7e01940479d4c94a82f5f | affected |
| Linux | Linux | a677ebd8ca2f2632ccdecbad7b87641274e15aac < f25e93768fcc5d8287e50b1ec52a42e4c276df34 | affected |
| Linux | Linux | 88b7f1143b15b29cccb8392b4f38e75b7bb3e300 | affected |
| Linux | Linux | 51a6c2af9d20203ddeeaf73314ba8854b38d01bd | affected |
| Linux | Linux | a637fabac554270a851033f5ab402ecb90bc479c | affected |
| Linux | Linux | 76af689a45aa44714b46d1a7de4ffdf851ded896 | affected |
| Linux | Linux | 5.15.157 < 5.16 | affected |
| Linux | Linux | 6.1.85 < 6.2 | affected |
| Linux | Linux | 6.6.26 < 6.7 | affected |
| Linux | Linux | 6.8.5 < 6.9 | affected |
| Linux | Linux | 6.9 | affected |
| Linux | Linux | 0 < 6.9 | unaffected |
| Linux | Linux | 7.2.6 <= 7.2.* | unaffected |
| Linux | Linux | 7.3-rc2 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/61a8d06600c8c397f9a7e01940479d4c94a82f5f
- https://git.kernel.org/stable/c/f25e93768fcc5d8287e50b1ec52a42e4c276df34
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.