Out-of-bounds read in Linux kernel - CVE-2026-89794
Published: September 17, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose uninitialized kernel heap memory.
The vulnerability exists due to an out-of-bounds read in the ksmbd smb2_read_pipe() function when handling compound SMB pipe read responses. A remote attacker can issue an SMB pipe read request that causes alignment padding to be included in a response to disclose uninitialized kernel heap memory.