In the Linux kernel, the following vulnerability has been resolved: fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath When cifs_sanitize_prepath is called with an empty string or a str…
High CVSS 8.8
Summary
In the Linux kernel, the following vulnerability has been resolved: fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath When cifs_sanitize_prepath is called with an empty string or a string containing only delimiters (e.g., "/"), the current logic attempts to check *(cursor2 - 1) before cursor2 has advanced. This results in an out-of-bounds read. This patch adds an early exit check after stripping prepended delimiters. If no path content remains, the function returns NULL. The bu…
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
Sources
- NVD DATABASE
Original Links
- https://git.kernel.org/stable/c/2d29214448ec0f4e7e18bb1c14dd4a6c07f1c439 Patch
- https://git.kernel.org/stable/c/49b1ce6d7cfb6c5a49f68bf5ccfcfb6ba14e63c3 Patch
- https://git.kernel.org/stable/c/5d4fe469fe7dbff7d874c196bb680a82f2625d95 Patch
- https://git.kernel.org/stable/c/78ec5bf2f589ec7fd8f169394bfeca541b077317 Patch
- https://git.kernel.org/stable/c/86f9c23e0814cfdffda9eedf0c591c51ba209010 Patch
- https://git.kernel.org/stable/c/a2ba20c17de8eb028f96b1d85f119d3d25655bd9
- https://git.kernel.org/stable/c/fbced33599653471b4581dfe1abc7b467031f126
- https://access.redhat.com/errata/RHSA-2026:34911
- https://access.redhat.com/errata/RHSA-2026:36018
- https://access.redhat.com/errata/RHSA-2026:36365
- https://access.redhat.com/errata/RHSA-2026:36366
- https://access.redhat.com/errata/RHSA-2026:40764
- https://access.redhat.com/security/cve/CVE-2026-43112
- https://bugzilla.redhat.com/show_bug.cgi?id=2467015
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-43112.json
Timeline
- nvd_ingest NVD