CVE-2026-46243

Source
https://cve.org/CVERecord?id=CVE-2026-46243
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-46243.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-46243
Downstream
Related
Published
2026-06-01T16:22:29.211Z
Modified
2026-06-11T03:55:59.952645672Z
Severity
  • 7.1 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N CVSS Calculator
Summary
smb: client: reject userspace cifs.spnego descriptions
Details

In the Linux kernel, the following vulnerability has been resolved:

smb: client: reject userspace cifs.spnego descriptions

cifs.spnego key descriptions contain authority-bearing fields such as pid, uid, creduid, and upcalltarget that cifs.upcall treats as kernel-originating inputs. However, userspace can also create keys of this type through requestkey(2) or add_key(2), allowing those fields to be supplied without CIFS origin.

Only accept cifs.spnego descriptions while CIFS is using its private spnego_cred to request the key.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/46xxx/CVE-2026-46243.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
f1d662a7d5e5322e583aad6b3cfec03d8f27b435
Fixed
7713bd320ed4fc3d08a227cd8e41242219a16981
Fixed
9544559e59438a4b609b2fdfa0763d8360572824
Fixed
cf20038657d6d4974349556a34e08fe0490bebbc
Fixed
2035acfb17221729b1b8ac335e941868a04ca079
Fixed
a3bbda6502a9398b816fa2e71c9a3f955f58013d
Fixed
91f89c1d83e80417629791fcef6af8140d7d01c8
Fixed
0aece6685fc80a8de492688ca2315fb86ec379c7
Fixed
3da1fdf4efbc490041eb4f836bf596201203f8f2

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-46243.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.6.24
Fixed
5.10.258
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.209
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.175
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.142
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.92
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.34
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.0.11

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-46243.json"