CVE-2026-93801: Linux
High severity, CVSS 7.0. EPSS: 0.1% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: smb/client: zero-initialize stack-allocated cifs_open_info_data Stack-allocated cifs_open_info_data may contain random data. This can make some fields have wrong value if they are not set later.
Affected products
- Linux Linux: from 6.12.54, before 6.12.111 (fixed in 6.12.111); from 6.6.113, before 6.7 (fixed in 6.7); from 6.17.4, before 6.18 (fixed in 6.18); from 6.18, before 6.18.53 (fixed in 6.18.53); from 6.19, before 7.2 (fixed in 7.2)
Published 2026-09-24. Last modified 2026-09-25.