NVD Vulnerability Detail
Search Exploit, PoC
CVE-2026-46243
Summary

In the Linux kernel, the following vulnerability has been resolved:

smb: client: reject userspace cifs.spnego descriptions

cifs.spnego key descriptions contain authority-bearing fields such as
pid, uid, creduid, and upcall_target that cifs.upcall treats as
kernel-originating inputs. However, userspace can also create keys of
this type through request_key(2) or add_key(2), allowing those fields to
be supplied without CIFS origin.

Only accept cifs.spnego descriptions while CIFS is using its private
spnego_cred to request the key.

Publication Date June 2, 2026, 2:17 a.m.
Registration Date June 2, 2026, 4:18 a.m.
Last Update June 2, 2026, 2:57 a.m.
Related information, measures and tools
Common Vulnerabilities List