In the Linux kernel, the following vulnerability has been resolved:
smb: client: reject userspace cifs.spnego descriptions
cifs.spnego key descriptions contain authority-bearing fields such as
pid, uid, creduid, and upcall_target that cifs.upcall treats as
kernel-originating inputs. However, userspace can also create keys of
this type through request_key(2) or add_key(2), allowing those fields to
be supplied without CIFS origin.
Only accept cifs.spnego descriptions while CIFS is using its private
spnego_cred to request the key.
References
Configurations
Configuration 1 (hide)
|
History
09 Jun 2026, 20:47
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:2.6.24:rc7:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:2.6.24:rc3:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:2.6.24:rc5:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:7.1:rc4:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:2.6.24:rc8:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:2.6.24:-:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:2.6.24:rc6:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:2.6.24:rc4:*:*:*:*:*:* |
|
| CWE | NVD-CWE-noinfo | |
| First Time |
Linux linux Kernel
Linux |
|
| References | () https://git.kernel.org/stable/c/0aece6685fc80a8de492688ca2315fb86ec379c7 - Patch | |
| References | () https://git.kernel.org/stable/c/2035acfb17221729b1b8ac335e941868a04ca079 - Patch | |
| References | () https://git.kernel.org/stable/c/3da1fdf4efbc490041eb4f836bf596201203f8f2 - Patch | |
| References | () https://git.kernel.org/stable/c/7713bd320ed4fc3d08a227cd8e41242219a16981 - Patch | |
| References | () https://git.kernel.org/stable/c/91f89c1d83e80417629791fcef6af8140d7d01c8 - Patch | |
| References | () https://git.kernel.org/stable/c/9544559e59438a4b609b2fdfa0763d8360572824 - Patch | |
| References | () https://git.kernel.org/stable/c/a3bbda6502a9398b816fa2e71c9a3f955f58013d - Patch | |
| References | () https://git.kernel.org/stable/c/cf20038657d6d4974349556a34e08fe0490bebbc - Patch | |
| References | () http://www.openwall.com/lists/oss-security/2026/06/01/6 - Mailing List, Third Party Advisory | |
| References | () https://github.com/manizada/CIFSwitch - Third Party Advisory |
05 Jun 2026, 07:16
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.1 |
01 Jun 2026, 21:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
01 Jun 2026, 19:16
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.8 |
| CWE | CWE-20 | |
| References |
|
01 Jun 2026, 17:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-01 17:17
Updated : 2026-06-09 20:47
NVD link : CVE-2026-46243
Mitre link : CVE-2026-46243
CVE.ORG link : CVE-2026-46243
JSON object : View
Products Affected
linux
- linux_kernel
CWE
