SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-43185

CRITICAL · CVSS 9.8 EPSS 0.62%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2026-05-06 · Last synced 2026-08-04

CyberRota Analysis

This is a critical severity vulnerability with a CVSS score of 9.8. It affects Linux.

CVE
CVE-2026-43185
Severity
CRITICAL
CVSS
9.8
EPSS
0.62%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix signededness bug in smb_direct_prepare_negotiation() smb_direct_prepare_negotiation() casts an unsigned __u32 value from sp->max_recv_size and req->preferred_send_size to a signed int before computing min_t(int, ...). A maliciously provided preferred_send_size of 0x80000000 will return as smaller than max_recv_size, and then be used to set the maximum allowed alowed receive size for the next message. By sending a second message with a large value (>1420 bytes) the attacker can then achieve a heap buffer overflow. This fix replaces min_t(int, ...) with min_t(u32)

Related CVEs

Other vulnerabilities affecting the same vendor(s)