Bug 2481486 (CVE-2026-46243) - CVE-2026-46243 kernel: Linux kernel: smb: client: reject userspace cifs.spnego descriptions
Summary: CVE-2026-46243 kernel: Linux kernel: smb: client: reject userspace cifs.spneg...
Keywords:
Status: NEW
Alias: CVE-2026-46243
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-05-26 15:09 UTC by OSIDB Bzimport
Modified: 2026-07-23 07:29 UTC (History)
5 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2026:23258 0 None None None 2026-06-04 12:22:25 UTC
Red Hat Product Errata RHSA-2026:23259 0 None None None 2026-06-04 12:15:41 UTC
Red Hat Product Errata RHSA-2026:23329 0 None None None 2026-06-04 14:53:41 UTC
Red Hat Product Errata RHSA-2026:23395 0 None None None 2026-06-04 16:00:43 UTC
Red Hat Product Errata RHSA-2026:24381 0 None None None 2026-06-08 12:55:48 UTC
Red Hat Product Errata RHSA-2026:25908 0 None None None 2026-06-15 02:04:22 UTC
Red Hat Product Errata RHSA-2026:26462 0 None None None 2026-06-17 01:14:04 UTC
Red Hat Product Errata RHSA-2026:26515 0 None None None 2026-06-17 06:33:41 UTC
Red Hat Product Errata RHSA-2026:26535 0 None None None 2026-06-17 09:18:51 UTC
Red Hat Product Errata RHSA-2026:26563 0 None None None 2026-06-17 11:58:39 UTC
Red Hat Product Errata RHSA-2026:26570 0 None None None 2026-06-17 13:19:48 UTC
Red Hat Product Errata RHSA-2026:27708 0 None None None 2026-06-22 05:56:06 UTC
Red Hat Product Errata RHSA-2026:27719 0 None None None 2026-06-22 02:40:25 UTC
Red Hat Product Errata RHSA-2026:27729 0 None None None 2026-06-22 04:27:00 UTC
Red Hat Product Errata RHSA-2026:27735 0 None None None 2026-06-22 06:02:12 UTC
Red Hat Product Errata RHSA-2026:28887 0 None None None 2026-07-01 11:16:18 UTC
Red Hat Product Errata RHSA-2026:28962 0 None None None 2026-07-06 12:51:38 UTC
Red Hat Product Errata RHSA-2026:33219 0 None None None 2026-06-29 19:39:20 UTC
Red Hat Product Errata RHSA-2026:33220 0 None None None 2026-06-29 19:43:20 UTC
Red Hat Product Errata RHSA-2026:33221 0 None None None 2026-06-29 19:24:50 UTC
Red Hat Product Errata RHSA-2026:33222 0 None None None 2026-06-29 19:39:33 UTC
Red Hat Product Errata RHSA-2026:33223 0 None None None 2026-06-29 19:42:06 UTC
Red Hat Product Errata RHSA-2026:33224 0 None None None 2026-06-29 19:43:37 UTC
Red Hat Product Errata RHSA-2026:33225 0 None None None 2026-06-29 22:42:08 UTC
Red Hat Product Errata RHSA-2026:33486 0 None None None 2026-06-30 11:28:47 UTC
Red Hat Product Errata RHSA-2026:34048 0 None None None 2026-07-09 20:00:09 UTC
Red Hat Product Errata RHSA-2026:34757 0 None None None 2026-07-09 13:51:36 UTC
Red Hat Product Errata RHSA-2026:34764 0 None None None 2026-07-07 14:22:29 UTC
Red Hat Product Errata RHSA-2026:34788 0 None None None 2026-07-07 12:38:53 UTC
Red Hat Product Errata RHSA-2026:34815 0 None None None 2026-07-08 09:33:57 UTC
Red Hat Product Errata RHSA-2026:36620 0 None None None 2026-07-16 10:50:08 UTC
Red Hat Product Errata RHSA-2026:40021 0 None None None 2026-07-23 07:29:43 UTC
Red Hat Product Errata RHSA-2026:41236 0 None None None 2026-07-17 12:52:35 UTC

Description OSIDB Bzimport 2026-05-26 15:09:34 UTC
cifs.spnego key descriptions contain authority-bearing fields such as
    pid, uid, creduid, and upcall_target that cifs.upcall treats as
    kernel-originating inputs. However, userspace can also create keys of
    this type through request_key(2) or add_key(2), allowing those fields to
    be supplied without CIFS origin.
    Only accept cifs.spnego descriptions while CIFS is using its private
    spnego_cred to request the key.

Comment 3 errata-xmlrpc 2026-06-04 12:15:40 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:23259 https://access.redhat.com/errata/RHSA-2026:23259

Comment 4 errata-xmlrpc 2026-06-04 12:22:24 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:23258 https://access.redhat.com/errata/RHSA-2026:23258

Comment 5 errata-xmlrpc 2026-06-04 14:53:40 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:23329 https://access.redhat.com/errata/RHSA-2026:23329

Comment 6 errata-xmlrpc 2026-06-04 16:00:42 UTC
This issue has been addressed in the following products:

  NVIDIA for RHEL 10

Via RHSA-2026:23395 https://access.redhat.com/errata/RHSA-2026:23395

Comment 7 errata-xmlrpc 2026-06-08 12:55:47 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:24381 https://access.redhat.com/errata/RHSA-2026:24381

Comment 8 errata-xmlrpc 2026-06-15 02:04:21 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10.0 Extended Update Support

Via RHSA-2026:25908 https://access.redhat.com/errata/RHSA-2026:25908

Comment 9 errata-xmlrpc 2026-06-17 01:14:03 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions

Via RHSA-2026:26462 https://access.redhat.com/errata/RHSA-2026:26462

Comment 10 errata-xmlrpc 2026-06-17 06:33:40 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions

Via RHSA-2026:26515 https://access.redhat.com/errata/RHSA-2026:26515

Comment 11 errata-xmlrpc 2026-06-17 09:18:50 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On

Via RHSA-2026:26535 https://access.redhat.com/errata/RHSA-2026:26535

Comment 12 errata-xmlrpc 2026-06-17 11:58:38 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.8 Telecommunications Update Service

Via RHSA-2026:26563 https://access.redhat.com/errata/RHSA-2026:26563

Comment 13 errata-xmlrpc 2026-06-17 13:19:47 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On

Via RHSA-2026:26570 https://access.redhat.com/errata/RHSA-2026:26570

Comment 15 errata-xmlrpc 2026-06-22 02:40:24 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 6 Extended Lifecycle Support  - EXTENSION

Via RHSA-2026:27719 https://access.redhat.com/errata/RHSA-2026:27719

Comment 16 errata-xmlrpc 2026-06-22 04:26:59 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7 Extended Lifecycle Support

Via RHSA-2026:27729 https://access.redhat.com/errata/RHSA-2026:27729

Comment 17 errata-xmlrpc 2026-06-22 05:56:04 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.6 Extended Update Support

Via RHSA-2026:27708 https://access.redhat.com/errata/RHSA-2026:27708

Comment 18 errata-xmlrpc 2026-06-22 06:02:11 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions

Via RHSA-2026:27735 https://access.redhat.com/errata/RHSA-2026:27735

Comment 19 errata-xmlrpc 2026-06-29 19:24:49 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions

Via RHSA-2026:33221 https://access.redhat.com/errata/RHSA-2026:33221

Comment 20 errata-xmlrpc 2026-06-29 19:39:18 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions

Via RHSA-2026:33219 https://access.redhat.com/errata/RHSA-2026:33219

Comment 21 errata-xmlrpc 2026-06-29 19:39:32 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions

Via RHSA-2026:33222 https://access.redhat.com/errata/RHSA-2026:33222

Comment 22 errata-xmlrpc 2026-06-29 19:42:05 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.6 Extended Update Support

Via RHSA-2026:33223 https://access.redhat.com/errata/RHSA-2026:33223

Comment 23 errata-xmlrpc 2026-06-29 19:43:18 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:33220 https://access.redhat.com/errata/RHSA-2026:33220

Comment 24 errata-xmlrpc 2026-06-29 19:43:36 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:33224 https://access.redhat.com/errata/RHSA-2026:33224

Comment 25 errata-xmlrpc 2026-06-29 22:42:07 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:33225 https://access.redhat.com/errata/RHSA-2026:33225

Comment 26 errata-xmlrpc 2026-06-30 11:28:46 UTC
This issue has been addressed in the following products:

  NVIDIA for RHEL 10

Via RHSA-2026:33486 https://access.redhat.com/errata/RHSA-2026:33486

Comment 27 errata-xmlrpc 2026-07-01 11:16:17 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.14

Via RHSA-2026:28887 https://access.redhat.com/errata/RHSA-2026:28887

Comment 28 errata-xmlrpc 2026-07-06 12:51:37 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.15

Via RHSA-2026:28962 https://access.redhat.com/errata/RHSA-2026:28962

Comment 29 errata-xmlrpc 2026-07-07 12:38:52 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.20

Via RHSA-2026:34788 https://access.redhat.com/errata/RHSA-2026:34788

Comment 30 errata-xmlrpc 2026-07-07 14:22:27 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.21

Via RHSA-2026:34764 https://access.redhat.com/errata/RHSA-2026:34764

Comment 31 errata-xmlrpc 2026-07-08 09:33:56 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.18

Via RHSA-2026:34815 https://access.redhat.com/errata/RHSA-2026:34815

Comment 32 errata-xmlrpc 2026-07-09 13:51:35 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.19

Via RHSA-2026:34757 https://access.redhat.com/errata/RHSA-2026:34757

Comment 33 errata-xmlrpc 2026-07-09 20:00:08 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.12

Via RHSA-2026:34048 https://access.redhat.com/errata/RHSA-2026:34048

Comment 34 errata-xmlrpc 2026-07-16 10:50:07 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.16

Via RHSA-2026:36620 https://access.redhat.com/errata/RHSA-2026:36620

Comment 35 errata-xmlrpc 2026-07-17 12:52:34 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7 Extended Lifecycle Support

Via RHSA-2026:41236 https://access.redhat.com/errata/RHSA-2026:41236

Comment 36 errata-xmlrpc 2026-07-23 07:29:42 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.13

Via RHSA-2026:40021 https://access.redhat.com/errata/RHSA-2026:40021


Note You need to log in before you can comment on or make changes to this bug.