Out-of-Bounds Read Vulnerability in Linux Kernel Affecting ksmbd
CVE-2026-89792
What is CVE-2026-89792?
A vulnerability has been identified in the Linux kernel's ksmbd component that may allow for out-of-bounds reads when processing IPC share configuration responses. This risk arises from inadequate validation of payload sizes prior to processing variable-length data fields. Specifically, it pertains to the parsing of veto lists and the handling of the separator byte which affects the calculation of the path length. This flaw can potentially lead to unauthorized data access, making it crucial for systems using the affected kernel versions to apply the necessary patches promptly.
Affected Version(s)
Linux a677ebd8ca2f2632ccdecbad7b87641274e15aac < 61a8d06600c8c397f9a7e01940479d4c94a82f5f
Linux a677ebd8ca2f2632ccdecbad7b87641274e15aac
Linux 88b7f1143b15b29cccb8392b4f38e75b7bb3e300