Out-of-bounds read in Linux kernel - CVE-2026-46149
Published: May 29, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in tg_pt_gp_members_show() when formatting and copying LUN paths to a sysfs reader. A local user can read the affected sysfs entry with a long fabric WWN value to disclose sensitive information.
When CONFIG_FORTIFY_SOURCE is enabled, exploitation triggers fortify_panic() instead of leaking adjacent stack contents.
How to mitigate CVE-2026-46149
Sources
- https://git.kernel.org/stable/c/00d91bfdce5033f5d9b4915638ae9b0553848b5d
- https://git.kernel.org/stable/c/1f678d13e939f91840cb1ebe9b88544923539d3c
- https://git.kernel.org/stable/c/72cc5ea7ef32bb5fa38bf0dd2e56fcd73aa8c89e
- https://git.kernel.org/stable/c/772a896a56e0e3ef9424a025cec9176f9d8f4552
- https://git.kernel.org/stable/c/e501154f9d82c95d2719bcbbaf679d8fd3226ef7