CVE-2026-52967
Severity CVSS v4.0:
Pending analysis
Type:
CWE-125
Out-of-bounds Read
Publication date:
24/06/2026
Last modified:
14/07/2026
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
smb/client: fix possible infinite loop and oob read in symlink_data()<br />
<br />
On 32-bit architectures, the infinite loop is as follows:<br />
<br />
len = p->ErrorDataLength == 0xfffffff8<br />
u8 *next = p->ErrorContextData + len<br />
next == p<br />
<br />
On 32-bit architectures, the out-of-bounds read is as follows:<br />
<br />
len = p->ErrorDataLength == 0xfffffff0<br />
u8 *next = p->ErrorContextData + len<br />
next == (u8 *)p - 8
Impact
Base Score 3.x
8.10
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.0.16 (including) | 6.1.175 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.2 (including) | 6.6.141 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.7 (including) | 6.12.91 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.13 (including) | 6.18.33 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.19 (including) | 7.0.10 (excluding) |
| cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/1b9331b16b0ed9414dcf7583d8134bdfeb117aae
- https://git.kernel.org/stable/c/1cfa2d59f669db28d6292d10ff87ca6837c781b0
- https://git.kernel.org/stable/c/7d9a7f1f96cd617ee9e75bb22217c709038e26b8
- https://git.kernel.org/stable/c/97a05b0ae9ea5ec052be2eef0f9cc7ce03501bbb
- https://git.kernel.org/stable/c/b41598bf54b3fe528994e573df6008f8f4d0a4f4
- https://git.kernel.org/stable/c/cd4b9b662f0fb9aa97ee6bf9034eca76fc6cab23



