Bug 2467015 (CVE-2026-43112)

Summary: CVE-2026-43112 kernel: fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: akhatavk, aos-team-art-private, asdas, dpaolell, jdelft, jupierce, lgarciaa, mbiarnes, ppalepu, ppostler, prdhamdh, rhel-process-autobot, sghai, sidsharm, suppawar, vlaad, watson-tool-maintainers
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in the Linux kernel's CIFS (Common Internet File System) client. When the `cifs_sanitize_prepath` function processes specially crafted input, such as an empty string or a string containing only delimiters, it can attempt to read data beyond its allocated memory buffer. This out-of-bounds read can lead to a system crash, resulting in a denial of service.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OSIDB Bzimport 2026-05-06 10:03:16 UTC
In the Linux kernel, the following vulnerability has been resolved:

fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath

When cifs_sanitize_prepath is called with an empty string or a string
containing only delimiters (e.g., "/"), the current logic attempts to
check *(cursor2 - 1) before cursor2 has advanced. This results in an
out-of-bounds read.

This patch adds an early exit check after stripping prepended
delimiters. If no path content remains, the function returns NULL.

The bug was identified via manual audit and verified using a
standalone test case compiled with AddressSanitizer, which
triggered a SEGV on affected inputs.

Comment 6 errata-xmlrpc 2026-07-02 13:42:29 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:34911 https://access.redhat.com/errata/RHSA-2026:34911

Comment 7 errata-xmlrpc 2026-07-06 19:57:13 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:36018 https://access.redhat.com/errata/RHSA-2026:36018

Comment 8 errata-xmlrpc 2026-07-07 21:16:05 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:36365 https://access.redhat.com/errata/RHSA-2026:36365

Comment 9 errata-xmlrpc 2026-07-07 21:33:55 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:36366 https://access.redhat.com/errata/RHSA-2026:36366

Comment 10 errata-xmlrpc 2026-07-21 15:13:26 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.22

Via RHSA-2026:40764 https://access.redhat.com/errata/RHSA-2026:40764

Comment 11 errata-xmlrpc 2026-08-10 05:35:25 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.8 Telecommunications Update Service

Via RHSA-2026:52649 https://access.redhat.com/errata/RHSA-2026:52649

Comment 12 errata-xmlrpc 2026-08-10 10:11:48 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10.0 Extended Update Support

Via RHSA-2026:52764 https://access.redhat.com/errata/RHSA-2026:52764

Comment 13 errata-xmlrpc 2026-08-12 00:41:27 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On

Via RHSA-2026:53989 https://access.redhat.com/errata/RHSA-2026:53989

Comment 14 errata-xmlrpc 2026-08-12 00:57:58 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.6 Extended Update Support

Via RHSA-2026:53990 https://access.redhat.com/errata/RHSA-2026:53990

Comment 15 errata-xmlrpc 2026-08-19 00:59:42 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions

Via RHSA-2026:56573 https://access.redhat.com/errata/RHSA-2026:56573

Comment 16 errata-xmlrpc 2026-08-25 13:52:13 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.21

Via RHSA-2026:57457 https://access.redhat.com/errata/RHSA-2026:57457

Comment 17 errata-xmlrpc 2026-08-25 13:54:32 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.20

Via RHSA-2026:57543 https://access.redhat.com/errata/RHSA-2026:57543

Comment 18 errata-xmlrpc 2026-08-26 00:18:07 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions

Via RHSA-2026:59663 https://access.redhat.com/errata/RHSA-2026:59663

Comment 19 errata-xmlrpc 2026-08-26 00:44:34 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions

Via RHSA-2026:59662 https://access.redhat.com/errata/RHSA-2026:59662

Comment 20 errata-xmlrpc 2026-08-26 16:32:54 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.19

Via RHSA-2026:57402 https://access.redhat.com/errata/RHSA-2026:57402

Comment 21 errata-xmlrpc 2026-09-02 09:56:07 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions

Via RHSA-2026:62558 https://access.redhat.com/errata/RHSA-2026:62558

Comment 22 errata-xmlrpc 2026-09-02 13:53:09 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions

Via RHSA-2026:62638 https://access.redhat.com/errata/RHSA-2026:62638

Comment 23 errata-xmlrpc 2026-09-02 14:00:09 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions

Via RHSA-2026:62639 https://access.redhat.com/errata/RHSA-2026:62639

Comment 24 errata-xmlrpc 2026-09-02 14:03:24 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:62642 https://access.redhat.com/errata/RHSA-2026:62642

Comment 25 errata-xmlrpc 2026-09-02 14:07:37 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:62640 https://access.redhat.com/errata/RHSA-2026:62640

Comment 26 errata-xmlrpc 2026-09-02 14:10:18 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:62637 https://access.redhat.com/errata/RHSA-2026:62637

Comment 27 errata-xmlrpc 2026-09-02 14:11:39 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.6 Extended Update Support

Via RHSA-2026:62641 https://access.redhat.com/errata/RHSA-2026:62641

Comment 28 errata-xmlrpc 2026-09-03 08:58:52 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.17

Via RHSA-2026:60019 https://access.redhat.com/errata/RHSA-2026:60019

Comment 29 errata-xmlrpc 2026-09-03 12:01:33 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.12

Via RHSA-2026:59831 https://access.redhat.com/errata/RHSA-2026:59831

Comment 30 errata-xmlrpc 2026-09-10 08:50:49 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.16

Via RHSA-2026:62549 https://access.redhat.com/errata/RHSA-2026:62549

Comment 31 Jon Orris 2026-09-14 13:30:45 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.14

Via RHSA-2026:62409 https://access.redhat.com/errata/RHSA-2026:62409

Comment 32 Jon Orris 2026-09-17 07:56:55 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.18

Via RHSA-2026:65851 https://access.redhat.com/errata/RHSA-2026:65851

Comment 33 Jon Orris 2026-09-17 17:11:23 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.13

Via RHSA-2026:65839 https://access.redhat.com/errata/RHSA-2026:65839