CVE-2026-89792

Summary

In the Linux kernel, the following vulnerability has been resolved:

ksmbd: prevent out-of-bounds reads in share config responses

Validate IPC share configuration payload sizes before consuming variable-length fields. Bound veto list parsing and account for the separator byte when deriving the path length.

Affected Software

VendorProductVersion RangeStatus
LinuxLinuxa677ebd8ca2f2632ccdecbad7b87641274e15aac < 61a8d06600c8c397f9a7e01940479d4c94a82f5faffected
LinuxLinuxa677ebd8ca2f2632ccdecbad7b87641274e15aac < f25e93768fcc5d8287e50b1ec52a42e4c276df34affected
LinuxLinux88b7f1143b15b29cccb8392b4f38e75b7bb3e300affected
LinuxLinux51a6c2af9d20203ddeeaf73314ba8854b38d01bdaffected
LinuxLinuxa637fabac554270a851033f5ab402ecb90bc479caffected
LinuxLinux76af689a45aa44714b46d1a7de4ffdf851ded896affected
LinuxLinux5.15.157 < 5.16affected
LinuxLinux6.1.85 < 6.2affected
LinuxLinux6.6.26 < 6.7affected
LinuxLinux6.8.5 < 6.9affected
LinuxLinux6.9affected
LinuxLinux0 < 6.9unaffected
LinuxLinux7.2.6 <= 7.2.*unaffected
LinuxLinux7.3-rc2 <= *unaffected

Weaknesses

References