
CVE-2026-46243
CIFSwitch
Local Privilege Escalation vulnerability affecting the Linux Kernel CIFS/SMB client.
CVE-2026-46243 is a Local Privilege Escalation (LPE) vulnerability within the Linux Kernel's CIFS/SMB client.
Improper validation of cifs.spnego key descriptions allows an unprivileged local user to impersonate trusted kernel-generated requests under specific system configurations, potentially resulting in privilege escalation.
Successful exploitation generally requires:
cifs-utilscifs.upcallAn attacker may be able to:
cifs-utils updatedThis repository is intended solely for educational, defensive security, and research purposes.
No offensive use is intended or supported.
Made with ❤️ by the Security Research Community
| 🆔 CVE | CVE-2026-46243 |
| 💻 Component | Linux Kernel |
| 📂 Subsystem | CIFS / SMB Client |
| ⚔️ Class | Local Privilege Escalation |
| 🎯 Attack Vector | Local |
| 🔐 Privileges Required | Low |
| 👤 User Interaction | None |
| ⚡ Impact | Privilege Escalation |