CVE-2026-43112 is an out-of-bounds read vulnerability in the Linux kernel SMB/CIFS client function cifs_sanitize_prepath. When given an empty string or a string containing only path delimiters, the function checks *(cursor2 - 1) before cursor2 has advanced, reading before the valid buffer. A standalone AddressSanitizer-enabled test reproduced a segmentation fault with affected inputs. The fix returns NULL when no path content remains after leading delimiters are stripped.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
37 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An out-of-bounds read in the Linux kernel SMB client’s cifs_sanitize_prepath function can occur when processing empty or delimiter-only paths. A standalone AddressSanitizer test confirmed a segmentation fault on affected inputs. The fix returns NULL when no path content remains after stripping leading delimiters. The reference reports a CVSS v3 base score of 8.1, although the vendor rates severity LOW.
An out-of-bounds read in the Linux kernel SMB client function cifs_sanitize_prepath occurs when processing empty or delimiter-only paths. A standalone AddressSanitizer test confirmed a segmentation fault on affected inputs. The fix returns NULL when no path content remains after stripping leading delimiters. The plugin reports a CVSS v3 base score of 8.1 and recommends updating affected Google COS kernel packages to version 19216.395.4 or later.
An out-of-bounds read in the Linux kernel SMB client's cifs_sanitize_prepath function occurs when processing empty or delimiter-only paths. A standalone AddressSanitizer test confirmed a segmentation fault on affected inputs. The fix returns NULL when no path content remains after removing leading delimiters. The reference lists a CVSS v3 base score of 8.1, although vendor severity is LOW.
An out-of-bounds read vulnerability in the Linux kernel SMB/CIFS client function cifs_sanitize_prepath. It affects the Red Hat Enterprise Linux 8 kpatch live-patch modules for kernel 4.18.0-477.97.1.el8_8 and related listed kpatch packages.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.