CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-46243

High · CVSS 7.1

Linux Kernel — Improper Input Validation / Dangling Pointer (Use-After-Free) via userspace-supplied cifs.spnego key descriptions

CVSS
7.1
nvd
EPSS
0.38%
30th pct
KEV
No
Class
oss containerizable
NVD-CWE-noinfo, CWE-20, CWE-825

Description

In the Linux kernel, the following vulnerability has been resolved: smb: client: reject userspace cifs.spnego descriptions cifs.spnego key descriptions contain authority-bearing fields such as pid, uid, creduid, and upcall_target that cifs.upcall treats as kernel-originating inputs. However, userspace can also create keys of this type through request_key(2) or add_key(2), allowing those fields to be supplied without CIFS origin. Only accept cifs.spnego descriptions while CIFS is using its private spnego_cred to request the key.

Search profile — drives PoC discovery

Symbols cifs.spnegospnego_credrequest_keyadd_keyupcall_targetcreduidpiduidcifs.upcallsmb/client
Keywords CVE-2026-46243Linux kernelsmb clientcifs spnegospnego_creduserspace key injectionrequest_key upcallcifs upcall privilege escalationNVD-CWE-noinfo CWE-20 CWE-825kernel smb cifs spnego description reject
Versions: Linux kernel versions prior to stable commits: 0aece6685fc8, 2035acfb1722, 3da1fdf4efbc, 7713bd320ed4, 91f89c1d83e8

Ranked PoCs (4) — best first

Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.

Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.

Affected packages

Linux Kernel 2.6.24 → 5.10.258
Linux Kernel 5.11.0 → 5.15.209
Linux Kernel 5.16.0 → 6.1.175
Linux Kernel 6.13.0 → 6.18.34
Linux Kernel 6.19.0 → 7.0.11
Linux Kernel 6.2.0 → 6.6.142
Linux Kernel 6.7.0 → 6.12.92

References

Status: enriched · ingested 2026-07-10T18:00:26.000Z · profiled 2026-07-10T18:30:26.000Z