Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1310 CNY

100%

CVE-2026-46243— smb: client: reject userspace cifs.spnego descriptions

AI Predicted 5.5 Difficulty: Moderate EPSS 0.02% · P4

Possible ATT&CK Techniques 1AI

T1558.003 · Kerberoasting

Affected Version Matrix 18

VendorProductVersion RangeStatus
LinuxLinuxf1d662a7d5e5322e583aad6b3cfec03d8f27b435< 7713bd320ed4fc3d08a227cd8e41242219a16981affected
f1d662a7d5e5322e583aad6b3cfec03d8f27b435< 9544559e59438a4b609b2fdfa0763d8360572824affected
f1d662a7d5e5322e583aad6b3cfec03d8f27b435< cf20038657d6d4974349556a34e08fe0490bebbcaffected
f1d662a7d5e5322e583aad6b3cfec03d8f27b435< 2035acfb17221729b1b8ac335e941868a04ca079affected
f1d662a7d5e5322e583aad6b3cfec03d8f27b435< a3bbda6502a9398b816fa2e71c9a3f955f58013daffected
f1d662a7d5e5322e583aad6b3cfec03d8f27b435< 91f89c1d83e80417629791fcef6af8140d7d01c8affected
f1d662a7d5e5322e583aad6b3cfec03d8f27b435< 0aece6685fc80a8de492688ca2315fb86ec379c7affected
f1d662a7d5e5322e583aad6b3cfec03d8f27b435< 3da1fdf4efbc490041eb4f836bf596201203f8f2affected
… +10 more rows
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-46243

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
smb: client: reject userspace cifs.spnego descriptions
Source: NVD (National Vulnerability Database)
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: smb: client: reject userspace cifs.spnego descriptions cifs.spnego key descriptions contain authority-bearing fields such as pid, uid, creduid, and upcall_target that cifs.upcall treats as kernel-originating inputs. However, userspace can also create keys of this type through request_key(2) or add_key(2), allowing those fields to be supplied without CIFS origin. Only accept cifs.spnego descriptions while CIFS is using its private spnego_cred to request the key.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
LinuxLinux f1d662a7d5e5322e583aad6b3cfec03d8f27b435 ~ 7713bd320ed4fc3d08a227cd8e41242219a16981 -
LinuxLinux 2.6.24 -

II. Public POCs for CVE-2026-46243

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-46243

登录查看更多情报信息。

Patches & Fixes for CVE-2026-46243 (7)

IV. Related Vulnerabilities

V. Comments for CVE-2026-46243

No comments yet


Leave a comment