CVE-2026-89792: Linux
High severity, CVSS 7.1. EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: ksmbd: prevent out-of-bounds reads in share config responses Validate IPC share configuration payload sizes before consuming variable-length fields. Bound veto list parsing and account for the separator byte when deriving the path length.
Affected products
- Linux Linux: from 5.15.157, before 5.15.222 (fixed in 5.15.222); from 6.1.85, before 6.1.189 (fixed in 6.1.189); from 6.6.26, before 6.6.158 (fixed in 6.6.158); from 6.8.5, before 6.9 (fixed in 6.9); from 6.9, before 6.12.111 (fixed in 6.12.111); from 6.13, before 6.18.53 (fixed in 6.18.53); …
Published 2026-09-16. Last modified 2026-10-03.