smb: client: reject userspace cifs.spnego descriptions
41Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 7.1epss 0.4%
from disclosure to weapon0 days
Published on NVDJun 1
1st PoCMay 30
exploitation probability
0.4%top 69% of all CVEs
observed exploitation
nono source reports it
6 public exploit(s)
In the Linux kernel, the following vulnerability has been resolved:
smb: client: reject userspace cifs.spnego descriptions
cifs.spnego key descriptions contain authority-bearing fields such as
pid, uid, creduid, and upcall_target that cifs.upcall treats as
kernel-originating inputs. However, userspace can also create keys of
this type through request_key(2) or add_key(2), allowing those fields to
be supplied without CIFS origin.
Only accept cifs.spnego descriptions while CIFS is using its private
spnego_cred to request the key.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Affected products
Linux · Linuxpublic PoCs found — 6
githubgithub.com/Koshmare-Blossom/CIFSwitch-go★ 2githubgithub.com/MrForkBomb/CIFSwitch-Checker-CVE-2026-46243★ 2githubgithub.com/liamromanis101/cifswitch-check★ 0githubgithub.com/0xBlackash/CVE-2026-46243★ 0githubgithub.com/suominen/cifswitch★ 0cve_referencegithub.com/manizada/CIFSwitchunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
https://access.redhat.com/errata/RHSA-2026:23258https://access.redhat.com/errata/RHSA-2026:23259https://access.redhat.com/errata/RHSA-2026:23329https://access.redhat.com/errata/RHSA-2026:23395https://access.redhat.com/errata/RHSA-2026:24381https://access.redhat.com/errata/RHSA-2026:25908https://access.redhat.com/errata/RHSA-2026:26462https://access.redhat.com/errata/RHSA-2026:26515https://access.redhat.com/errata/RHSA-2026:26535https://access.redhat.com/errata/RHSA-2026:26563https://access.redhat.com/errata/RHSA-2026:26570https://access.redhat.com/errata/RHSA-2026:27708