Bug 2481486 (CVE-2026-46243) - CVE-2026-46243 kernel: Linux kernel: smb: client: reject userspace cifs.spnego descriptions
Summary: CVE-2026-46243 kernel: Linux kernel: smb: client: reject userspace cifs.spneg...
Keywords:
Status: NEW
Alias: CVE-2026-46243
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-05-26 15:09 UTC by OSIDB Bzimport
Modified: 2026-06-04 16:00 UTC (History)
5 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2026:23258 0 None None None 2026-06-04 12:22:25 UTC
Red Hat Product Errata RHSA-2026:23259 0 None None None 2026-06-04 12:15:41 UTC
Red Hat Product Errata RHSA-2026:23329 0 None None None 2026-06-04 14:53:41 UTC
Red Hat Product Errata RHSA-2026:23395 0 None None None 2026-06-04 16:00:43 UTC

Description OSIDB Bzimport 2026-05-26 15:09:34 UTC
cifs.spnego key descriptions contain authority-bearing fields such as
    pid, uid, creduid, and upcall_target that cifs.upcall treats as
    kernel-originating inputs. However, userspace can also create keys of
    this type through request_key(2) or add_key(2), allowing those fields to
    be supplied without CIFS origin.
    Only accept cifs.spnego descriptions while CIFS is using its private
    spnego_cred to request the key.

Comment 3 errata-xmlrpc 2026-06-04 12:15:40 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:23259 https://access.redhat.com/errata/RHSA-2026:23259

Comment 4 errata-xmlrpc 2026-06-04 12:22:24 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:23258 https://access.redhat.com/errata/RHSA-2026:23258

Comment 5 errata-xmlrpc 2026-06-04 14:53:40 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:23329 https://access.redhat.com/errata/RHSA-2026:23329

Comment 6 errata-xmlrpc 2026-06-04 16:00:42 UTC
This issue has been addressed in the following products:

  NVIDIA for RHEL 10

Via RHSA-2026:23395 https://access.redhat.com/errata/RHSA-2026:23395


Note You need to log in before you can comment on or make changes to this bug.