Executive brief
A vulnerability exists in the Linux kernel's ksmbd component, which provides SMB file sharing services. An attacker can exploit a flaw in how the system processes security descriptors to cause the server to read memory outside of intended boundaries. This can lead to unauthorized changes to file permissions or system instability, potentially impacting the confidentiality and availability of shared data.
Technical details
An out-of-bounds read vulnerability exists in the ksmbd SMB server within the parse_dacl() function in fs/smb/server/smbacl.c. The vulnerability occurs because the code compares ACE SIDs against sid_unix_NFS_mode without verifying that the SID contains a sufficient number of sub-authorities. If a SID with only two sub-authorities is provided at the end of a security descriptor, the code attempts to read a third sub-authority (sub_auth[2]), resulting in a 4-byte read past the end of the ACL buffer. This out-of-band data is then applied as the file's POSIX mode. The issue has been patched by requiring at least three sub-authorities before attempting the read.
Affected products
- Linux Linux Kernel 5.15 to 6.6.136, 6.7 to 6.12.83, 6.13 to 6.18.24, 6.19 to 6.19.14, 7.0 to 7.0.1
Timeline
- 2026-04-24: disclosed
- 2026-04-24: advisory
- 2026-04-06: patched: Initial patch authored
References
- https://git.kernel.org/stable/c/08f9e6d899b5c834bbcc239eae1bed58d9b15d2c
- https://git.kernel.org/stable/c/46bbcd3ebfb3549c8da1838fc4493e79bd3241e7
- https://git.kernel.org/stable/c/53370cf9090777774e07fd9a8ebce67c6cc333ab
- https://git.kernel.org/stable/c/9401f86a224f37b50e6a3ccf1d46a70d5ef8af0a
- https://git.kernel.org/stable/c/b5b5d5936a50497fb151c0b122899a6894721c2b
- https://git.kernel.org/stable/c/cf2148b880fb7c0fcd727202dbc4fd5d6998b9c2
- https://git.kernel.org/stable/c/d2454f4a002d08560a60f214f392e6491cf11560