Out-of-bounds read in Linux kernel - CVE-2026-43112
Published: May 7, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to out-of-bounds read in cifs_sanitize_prepath when parsing path strings containing only delimiters or no path content. A local user can supply a crafted path string to cause a denial of service.
The issue can be triggered by an empty string or a string such as "/".
How to mitigate CVE-2026-43112
Sources
- https://git.kernel.org/stable/c/2d29214448ec0f4e7e18bb1c14dd4a6c07f1c439
- https://git.kernel.org/stable/c/49b1ce6d7cfb6c5a49f68bf5ccfcfb6ba14e63c3
- https://git.kernel.org/stable/c/5d4fe469fe7dbff7d874c196bb680a82f2625d95
- https://git.kernel.org/stable/c/78ec5bf2f589ec7fd8f169394bfeca541b077317
- https://git.kernel.org/stable/c/86f9c23e0814cfdffda9eedf0c591c51ba209010