Fedora Account System
Red Hat Associate
Red Hat Customer
In the Linux kernel, the following vulnerability has been resolved: smb/client: fix out-of-bounds read in symlink_data() Since smb2_check_message() returns success without length validation for the symlink error response, in symlink_data() it is possible for iov->iov_len to be smaller than sizeof(struct smb2_err_rsp). If the buffer only contains the base SMB2 header (64 bytes), accessing err->ErrorContextCount (at offset 66) or err->ByteCount later in symlink_data() will cause an out-of-bounds read.
Upstream advisory: https://lore.kernel.org/linux-cve-announce/2026052830-CVE-2026-46185-42df@gregkh/T
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:57251 https://access.redhat.com/errata/RHSA-2026:57251
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:63129 https://access.redhat.com/errata/RHSA-2026:63129