PT-2026-44318 · Linux+2 · Linux Kernel+2

CVE-2026-46195

·

Published

2026-05-28

·

Updated

2026-09-07

CVSS v3.1

7.5

High

VectorAV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the SMB client where the server-supplied dacloffset is added to pntsd before verifying if a DACL header fits within the returned security descriptor. On 32-bit builds, a malicious server can provide a dacloffset value near U32 MAX, causing the derived DACL pointer to wrap around below end of acl and bypass pointer-based bounds checks. This allows the build sec desc() and id mode to cifs acl() functions to dereference DACL fields from the wrapped pointer during chmod or chown rewrite paths. The affected functions include parse sec desc(), build sec desc(), and the chown path in id mode to cifs acl().
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

NULL Pointer Dereference

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-89013
CVE-2026-46195
ECHO-C1E1-4615-F038
LSN-0121-1
OPENSUSE-SU-2026:10954-1
USN-8488-1
USN-8488-2
USN-8489-1
USN-8490-1
USN-8490-2
USN-8491-1
USN-8492-1
USN-8492-2
USN-8492-3
USN-8492-4
USN-8492-5
USN-8493-1
USN-8493-2
USN-8497-1
USN-8498-1
USN-8499-1
USN-8507-1
USN-8508-1
USN-8527-1
USN-8528-1
USN-8545-1
USN-8546-1
USN-8547-1
USN-8547-2
USN-8569-1
USN-8603-1
USN-8604-1
USN-8605-1
USN-8606-1
USN-8607-1
USN-8609-1
USN-8619-1
USN-8728-1

Affected Products

Linuxmint
Linux Kernel
Ubuntu