CVE-2026-43185General(linux / linux_kernel)

LOWCVSS 9.8 · CRITICAL

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Patch linux linux_kernel systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix signededness bug in smb_direct_prepare_negotiation() smb_direct_prepare_negotiation() casts an unsigned __u32 value from sp->max_recv_size and req->preferred_send_size to a signed int before computing min_t(int, ...). A maliciously provided preferred_send_size of 0x80000000 will return as smaller than max_recv_size, and then be used to set the maximum allowed alowed receive size for the next message. By sending a second message with a large value (>1420 bytes) the attacker can then achieve a heap buffer overflow. This fix replaces min_t(int, ...) with min_t(u32)

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-674

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linux_kernel

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • 4 total mentions across 1 day

Affected systems

Vendors
Products
linux_kernel

1 version affected across 1 product

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-05-14: 4Patch / Workaround · 2026-05-14: 1Technical Details · 2026-05-14: 305-14
Signal classification3 categories
General
250.0%
Disclosure
125.0%
Patch
125.0%
Referenced assets1 URL
By indicator
Full discourse4 posts
  • Lyrie.ai@lyrie_ai
    Disclosure

    By sending a second message with a large value (>1420 bytes) the attacker can then achieve a heap buffer overflow. CVE: CVE-2026-43185 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The advisory discloses a critical heap buffer overflow in CVE-2026-43185, providing technical details and severity assessment without mentioning PoC, exploit code, active exploitation, or a patch.

    1000030
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Patch

    CVE: CVE-2026-43185 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix signededness bug in smbdirectpreparenegotiation()…

    Post summary

    The advisory announces that CVE-2026-43185 has been fixed in the Linux kernel, providing CVSS details but no PoC or active exploitation information.

    1000032
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    CRITICAL: CVE-2026-43185 (CVSS 9.8) — multiple products. CVE: CVE-2026-43185 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The post simply announces CVE-2026-43185 as a critical vulnerability with a CVSS 9.8 score, without any additional technical, exploit, or mitigation information.

    1000025
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-43185-advisory #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The provided text only references a CVE via a URL and generic hashtags; no substantive evidence of PoC, exploit, exploitation, patching, technical details, or debunking is included.

    0000021
    210 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
OSlinuxlinux_kernel---
OSlinuxlinux_kernel7.0--

Explore more