๐Ÿ” CVE Alert

CVE-2026-68100

UNKNOWN 0.0

ksmbd: validate num_subauth when copying ACE in set_ntacl_dacl

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate num_subauth when copying ACE in set_ntacl_dacl set_ntacl_dacl() copies each ACE from the attacker-controlled stored security descriptor verbatim into the response DACL without checking sid.num_subauth. The ACE bytes (including an unchecked num_subauth) originate from an authenticated SMB2_SET_INFO(SecInfo=DACL) that is stored raw via ksmbd_vfs_set_sd_xattr(); parse_dacl() rejects a bad ACE with `break` rather than an error, so parse_sec_desc() still returns success and the malformed SD reaches the xattr intact. On a subsequent SMB2_QUERY_INFO(SecInfo=DACL) for an inode carrying a POSIX access ACL, build_sec_desc() -> set_ntacl_dacl() -> set_posix_acl_entries_dacl() walks the copied ACEs and reads ntace->sid.sub_auth[ntace->sid.num_subauth - 1] with num_subauth taken straight from the stored SD. Since sub_auth[] is fixed at SID_MAX_SUB_AUTHORITIES (15), a crafted num_subauth (e.g. 255) drives an out-of-bounds heap read of ~1 KB with an offset fully controlled by an authenticated client. The sibling functions already gate this field: parse_dacl() -- num_subauth == 0 || > SID_MAX_SUB_AUTHORITIES parse_sid() -- num_subauth > SID_MAX_SUB_AUTHORITIES smb_copy_sid() -- min_t(u8, num_subauth, SID_MAX_SUB_AUTHORITIES) set_ntacl_dacl() is the lone inconsistent path that omits the check. Add the same num_subauth validation in set_ntacl_dacl() before copying the ACE, matching the gate already enforced by parse_dacl().

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Aug 10, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < e31fada5143784bc05c7ae44c79eed9b7a2e147e 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < fb3dc8e6da46a1ccad1956cda57de29d9b3033e0 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < b6d3cc6a524416dfdb2b47e4bba2e7e20011d056 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 5acbd3012fd4a7ccfebd91ea6f784120084eb897 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 47f0b34f6bc98ed85bfdc293e8f3e432ec24958d 0 < 6.6.148 0 < 6.12.101 0 < 6.18.42 0 < 7.1.6
Linux / Linux
All versions affected

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/e31fada5143784bc05c7ae44c79eed9b7a2e147e git.kernel.org: https://git.kernel.org/stable/c/fb3dc8e6da46a1ccad1956cda57de29d9b3033e0 git.kernel.org: https://git.kernel.org/stable/c/b6d3cc6a524416dfdb2b47e4bba2e7e20011d056 git.kernel.org: https://git.kernel.org/stable/c/5acbd3012fd4a7ccfebd91ea6f784120084eb897 git.kernel.org: https://git.kernel.org/stable/c/47f0b34f6bc98ed85bfdc293e8f3e432ec24958d