Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4353 articles · 196293 vulns · 36/41 feeds (7d)
← Back to list
7.1
CVE-2026-46243EXPLOITEDPATCHED
linux · linux_kernel

smb: client: reject userspace cifs.spnego descriptions

Description

In the Linux kernel, the following vulnerability has been resolved: smb: client: reject userspace cifs.spnego descriptions cifs.spnego key descriptions contain authority-bearing fields such as pid, uid, creduid, and upcall_target that cifs.upcall treats as kernel-originating inputs. However, userspace can also create keys of this type through request_key(2) or add_key(2), allowing those fields to be supplied without CIFS origin. Only accept cifs.spnego descriptions while CIFS is using its private spnego_cred to request the key.

Affected Products

VendorProductVersions
linuxlinux_kernelf1d662a7d5e5322e583aad6b3cfec03d8f27b435, f1d662a7d5e5322e583aad6b3cfec03d8f27b435, f1d662a7d5e5322e583aad6b3cfec03d8f27b435, f1d662a7d5e5322e583aad6b3cfec03d8f27b435, f1d662a7d5e5322e583aad6b3cfec03d8f27b435, f1d662a7d5e5322e583aad6b3cfec03d8f27b435, f1d662a7d5e5322e583aad6b3cfec03d8f27b435, f1d662a7d5e5322e583aad6b3cfec03d8f27b435, 2.6.24

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
linuxlinuxmitre_affected90%
open sourceopen source linux kernelcert_advisory90%

References

  • https://git.kernel.org/stable/c/7713bd320ed4fc3d08a227cd8e41242219a16981
  • https://git.kernel.org/stable/c/9544559e59438a4b609b2fdfa0763d8360572824
  • https://git.kernel.org/stable/c/cf20038657d6d4974349556a34e08fe0490bebbc
  • https://git.kernel.org/stable/c/2035acfb17221729b1b8ac335e941868a04ca079
  • https://git.kernel.org/stable/c/a3bbda6502a9398b816fa2e71c9a3f955f58013d
  • https://git.kernel.org/stable/c/91f89c1d83e80417629791fcef6af8140d7d01c8
  • https://git.kernel.org/stable/c/0aece6685fc80a8de492688ca2315fb86ec379c7
  • https://git.kernel.org/stable/c/3da1fdf4efbc490041eb4f836bf596201203f8f2

Related News (13 articles)

Tier B
CERT-FR9d ago
Multiples vulnérabilités dans le noyau Linux de SUSE (14 août 2026)
→ No new info (linked only)
Tier B
CERT-FR9d ago
Multiples vulnérabilités dans le noyau Linux d'Ubuntu (14 août 2026)
→ No new info (linked only)
Tier B
CERT-FR16d ago
Multiples vulnérabilités dans les produits IBM (07 août 2026)
→ No new info (linked only)
Tier B
CERT-FR23d ago
Multiples vulnérabilités dans le noyau Linux de SUSE (31 juillet 2026)
→ No new info (linked only)
Tier B
CERT-FR30d ago
Multiples vulnérabilités dans le noyau Linux de Red Hat (24 juillet 2026)
→ No new info (linked only)
Tier B
CERT-FR30d ago
Multiples vulnérabilités dans le noyau Linux de SUSE (24 juillet 2026)
→ No new info (linked only)
Tier A
Microsoft MSRC56d ago
CVE-2026-46243 smb: client: reject userspace cifs.spnego descriptions
→ No new info (linked only)
Tier B
CERT-FR65d ago
Multiples vulnérabilités dans le noyau Linux de Red Hat (19 juin 2026)
→ No new info (linked only)
Tier B
CERT-FR79d ago
Multiples vulnérabilités dans le noyau Linux de Red Hat (05 juin 2026)
→ No new info (linked only)
Tier B
BSI Advisories82d ago
[NEU] [mittel] Linux Kernel: Schwachstelle ermöglicht Privilegieneskalation
→ No new info (linked only)
Tier C
VulDB83d ago
CVE-2026-46243 | Linux Kernel up to 7.1-rc4 smb upcall_target privilege escalation
→ No new info (linked only)
Tier C
oss-security83d ago
Re: CIFSwitch: Linux kernel/cifs-utils local root via forged cifs.spnego upcall
→ No new info (linked only)
Tier C
Linux Kernel CVEs83d ago
CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions
→ No new info (linked only)
CVSS 3.17.1 HIGH
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
7713bd320ed4fc3d08a227cd8e41242219a169819544559e59438a4b609b2fdfa0763d8360572824cf20038657d6d4974349556a34e08fe0490bebbc2035acfb17221729b1b8ac335e941868a04ca079a3bbda6502a9398b816fa2e71c9a3f955f58013d91f89c1d83e80417629791fcef6af8140d7d01c80aece6685fc80a8de492688ca2315fb86ec379c73da1fdf4efbc490041eb4f836bf596201203f8f205.10.2585.15.2096.1.1756.6.1426.12.926.18.347.0.117.1-rc5
PublishedJun 1, 2026
Last enriched83d agov3
Tags
local rootCIFScifs-utils
Trending Score20
Source articles13
Independent6
Info Completeness8/14
Missing: cvss, epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-46331EXP
net/sched: fix pedit partial COW leading to page cache corruption
Trending: 65
HIGHCVE-2026-53359EXP
KVM: x86: Fix shadow paging use-after-free due to unexpected role
Trending: 65
HIGHCVE-2026-64600EXP
xfs: resample the data fork mapping after cycling ILOCK
Trending: 56
HIGHCVE-2026-46242EXP
eventpoll: fix ep_remove struct eventpoll / struct file UAF
Trending: 51
HIGHCVE-2026-53366EXP
ipv4: account for fraggap on the paged allocation path
Trending: 50

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jun 1, 2026
Discovered by ZDM
Jun 1, 2026
Updated: affectedVersions, cweIds, tags
Jun 1, 2026
Updated: description, affectedVersions, severity
Jun 1, 2026
Actively Exploited
Aug 7, 2026
Exploit Available
Aug 7, 2026
Patch Available
Aug 7, 2026

Version History

v3
Last enriched 83d ago
v3Tier C83d ago

Updated description with critical vulnerability details, changed severity to CRITICAL, and added affected version 7.1-rc4.

descriptionaffectedVersionsseverity
via VulDB
v2Tier C83d ago

Updated description with technical details, added affected versions, changed severity to HIGH, added CWE-20, and marked exploit as available and actively exploited.

affectedVersionscweIdstags
via oss-security
v183d ago

Initial creation