CVE-2026-46149 Details
Description
In the Linux kernel, the following vulnerability has been resolved: scsi: target: configfs: Bound snprintf() return in tg_pt_gp_members_show() target_tg_pt_gp_members_show() formats LUN paths with snprintf() into a 256-byte stack buffer, then will memcpy() cur_len bytes from that buffer. snprintf() returns the length the output would have had, which can exceed the buffer size when the fabric WWN is long because iSCSI IQN names can be up to 223 bytes. The check at the memcpy() site only guards the destination page write, not the source read, so memcpy() will read past the stack buffer and copy adjacent stack contents to the sysfs reader, which when CONFIG_FORTIFY_SOURCE is enabled, fortify_panic() will be triggered. Commit 27e06650a5ea ("scsi: target: target_core_configfs: Add length check to avoid buffer overflow") added the same bound to the target_lu_gp_members_show() but the tg_pt_gp variant was missed so resolve that here.
A buffer overflow vulnerability has been identified in the Linux kernel's SCSI target configuration subsystem. The issue arises in the 'tg_pt_gp_members_show()' function, which formats Logical Unit Number (LUN) paths using 'snprintf()' into a 256-byte stack buffer. The function then uses 'memcpy()' to transfer data based on the length reported by 'snprintf()', which can exceed the buffer size, particularly when the fabric World Wide Name (WWN) is long, as iSCSI IQN names can be up to 223 bytes. This oversight allows 'memcpy()' to read beyond the allocated buffer, copying adjacent stack contents to the sysfs reader. When 'CONFIG_FORTIFY_SOURCE' is enabled, this behavior triggers a panic. The vulnerability affects several versions of the Linux kernel.
Users can upgrade to the latest stable version of the Linux kernel, where this vulnerability has been addressed. Instructions for downloading the latest version can be found on the official Linux kernel website.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/00d91bfdce5033f5d9b4915638ae9b0553848b5d | kernel.org | Patch |
| https://git.kernel.org/stable/c/12f2201a56957ba020392223a7393a5eba080c1b | kernel.org | Patch |
| https://git.kernel.org/stable/c/1f678d13e939f91840cb1ebe9b88544923539d3c | kernel.org | Patch |
| https://git.kernel.org/stable/c/72cc5ea7ef32bb5fa38bf0dd2e56fcd73aa8c89e | kernel.org | Patch |
| https://git.kernel.org/stable/c/772a896a56e0e3ef9424a025cec9176f9d8f4552 | kernel.org | Patch |
| https://git.kernel.org/stable/c/d3cc9d490c207d57a289054397349f6f8c90354e | kernel.org | Patch |
| https://git.kernel.org/stable/c/db0a4759d62cad4ff891e2d81ae4be73bb57f4a4 | kernel.org | Patch |
| https://git.kernel.org/stable/c/e501154f9d82c95d2719bcbbaf679d8fd3226ef7 | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-674 | Uncontrolled Recursion | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 2.6.38, < 5.10.258 >= 5.11, < 5.15.209 >= 5.16, < 6.1.175 >= 6.2, < 6.6.140 >= 6.7, < 6.12.88 >= 6.13, < 6.18.30 >= 6.19, < 7.0.7 7.1 rc1 7.1 rc2 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | kernel.org |
| Jun 10, 2026 | Initial Analysis | [email protected] |
| Jun 1, 2026 | CVE Modified | kernel.org |
| May 30, 2026 | CVE Modified | kernel.org |
| May 28, 2026 | New CVE Received | kernel.org |