smb: client: reject userspace cifs.spnego descriptions
41Vexday Risk Score
Sin señal de explotación. Ella tiene prueba de concepto pública.
ssvc Attendcvss 7.1epss 0.4%
de la publicación al arma0 días
Publicada en NVD1 jun
1ª PoC30 may
probabilidad de explotación
0.4%top 69% de las CVE
explotación observada
noninguna fuente lo reporta
6 exploit(s) público(s)
In the Linux kernel, the following vulnerability has been resolved:
smb: client: reject userspace cifs.spnego descriptions
cifs.spnego key descriptions contain authority-bearing fields such as
pid, uid, creduid, and upcall_target that cifs.upcall treats as
kernel-originating inputs. However, userspace can also create keys of
this type through request_key(2) or add_key(2), allowing those fields to
be supplied without CIFS origin.
Only accept cifs.spnego descriptions while CIFS is using its private
spnego_cred to request the key.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Productos afectados
Linux · LinuxPoCs públicas encontradas — 6
githubgithub.com/Koshmare-Blossom/CIFSwitch-go★ 2githubgithub.com/MrForkBomb/CIFSwitch-Checker-CVE-2026-46243★ 2githubgithub.com/liamromanis101/cifswitch-check★ 0githubgithub.com/0xBlackash/CVE-2026-46243★ 0githubgithub.com/suominen/cifswitch★ 0cve_referencegithub.com/manizada/CIFSwitchno verificado⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.
Referencias
https://access.redhat.com/errata/RHSA-2026:23258https://access.redhat.com/errata/RHSA-2026:23259https://access.redhat.com/errata/RHSA-2026:23329https://access.redhat.com/errata/RHSA-2026:23395https://access.redhat.com/errata/RHSA-2026:24381https://access.redhat.com/errata/RHSA-2026:25908https://access.redhat.com/errata/RHSA-2026:26462https://access.redhat.com/errata/RHSA-2026:26515https://access.redhat.com/errata/RHSA-2026:26535https://access.redhat.com/errata/RHSA-2026:26563https://access.redhat.com/errata/RHSA-2026:26570https://access.redhat.com/errata/RHSA-2026:27708