Out-of-bounds read in Linux kernel - CVE-2026-93787
Published: September 25, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause an out-of-bounds read.
The vulnerability exists due to improper bounds checking in cifs_filldir() when processing SMB1 TRANS2 directory enumeration responses. A remote attacker can return a directory entry with an oversized FileNameLength to cause an out-of-bounds read.
User interaction is required to list a directory on a CIFS mount served by an attacker-controlled SMB1 server.