CVE-2026-93801

Published: Set 24, 2026 Last Modified: Set 25, 2026
ExploitDB:
Other exploit source:
Google Dorks:
HIGH 7,0
Source: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Attack Vector: local
Attack Complexity: high
Privileges Required: low
User Interaction: none
Scope: unchanged
Confidentiality: high
Integrity: high
Availability: high

Description

AI Translation Available

In the Linux kernel, the following vulnerability has been resolved:

smb/client: zero-initialize stack-allocated cifs_open_info_data

Stack-allocated cifs_open_info_data may contain random data.
This can make some fields have wrong value if they are not set later.

https://git.kernel.org/stable/c/22532dd88694ed20bdd47523ffa709f166ce776b
https://git.kernel.org/stable/c/74ff47e6c4213fcfeba2de448d9cbda200507d22
https://git.kernel.org/stable/c/8fce4cf4369c766a3293a05419500cbfde72e60d