Out-of-bounds read in Linux kernel - CVE-2026-46155
Published: May 29, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in smb2_compound_op() when processing a crafted SMB server response. A remote attacker can send a truncated response with a large OutputBufferLength and an early-terminated EA list to disclose sensitive information.
Affected software
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support
Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support
Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support
Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Ubuntu
kernel (Red Hat package)
linux (Ubuntu package)
linux-azure (Ubuntu package)
linux-gcp-7.0 (Ubuntu package)
linux-nvidia (Ubuntu package)
linux-raspi (Ubuntu package)
How to mitigate CVE-2026-46155
linux (Ubuntu package) - update to 7.0.0-27.27
linux-azure (Ubuntu package) - addressed in versions 7.0.0-1009.9, 7.0.0-1010.10
linux-gcp-7.0 (Ubuntu package) - update to 7.0.0-1011.11~24.04.1
linux-nvidia (Ubuntu package) - update to 7.0.0-1013.13
linux-raspi (Ubuntu package) - update to 7.0.0-1014.14
External References
- https://git.kernel.org/stable/c/512d33bc8ea4ea5c19728ee118715f4b1f4d1926
- https://git.kernel.org/stable/c/8d09328dfda089675e4c049f3f256064a1d1996b
- https://git.kernel.org/stable/c/9b3af35645ff9cd334edc130249f9a2fb2bea25f
- https://git.kernel.org/stable/c/a16f70a71be4b5a4eccf39a9bf09b47285f4cb7c
- https://git.kernel.org/stable/c/dffb44b2e06a2908e249f0f93156fc987eee1d1c
Related Security Bulletins
- Out-of-bounds read in Linux kernel smb client
- Ubuntu update for linux
- Ubuntu update for linux-raspi
- Ubuntu update for linux-nvidia
- Red Hat Enterprise Linux 9 update for kernel
- Red Hat Enterprise Linux 10 update for kernel
- Ubuntu update for linux-azure
- Ubuntu update for linux-gcp-7.0
- Red Hat Enterprise Linux 10 update for kernel