Out-of-bounds read in Linux kernel - CVE-2026-89792
Published: September 17, 2026
Vulnerability details
The vulnerability allows a local user to disclose sensitive information and cause a denial of service.
The vulnerability exists due to out-of-bounds read in the ksmbd share configuration response handling when processing IPC share configuration responses with malformed variable-length fields. A local user can provide a crafted share configuration response to disclose sensitive information and cause a denial of service.