Executive brief
A vulnerability exists in the Linux kernel's ksmbd component, which provides SMB file sharing services. An error in how the system checks file permissions could allow an attacker to read small amounts of memory they should not have access to. This could potentially lead to the exposure of sensitive system information, though it does not directly allow for data modification or system takeover.
Technical details
A regression was introduced in the ksmbd component of the Linux kernel due to an incorrect bounds check in the smb_check_perm_dacl() function. Specifically, a transposed comparison resulted in dead code that failed to validate the size of Access Control Entries (ACE) during a loop walk. This allows a 2-byte heap out-of-bounds (OOB) read when processing SMB2_CREATE operations with specially crafted DACLs. An attacker can exploit this to read memory past the allocated buffer. The issue has been resolved by correcting the logic to require a minimum of 16 bytes for the ACE structure.
Affected products
- Linux Linux Kernel 6.6.140 to 6.6.143, 6.12.84 to 6.12.93
Timeline
- 2026-05-25: other: Patch authored
- 2026-07-19: disclosed: CVE published
References
- https://git.kernel.org/stable/c/0e60dafe97eca61721f3db456f97d97a80c6c8ae
- https://git.kernel.org/stable/c/0fe08c5776a798f46df1fd74b331be26bdd644d6
- https://git.kernel.org/stable/c/4f7c131d2bdd7cd64b96f60d10be5ea72253f520
- https://git.kernel.org/stable/c/5500ba1d410aed1eded3eb04a76b10cfb4409334
- https://git.kernel.org/stable/c/94215d55b09445993929f4fc966061d61de74929
- https://git.kernel.org/stable/c/d333af32e4451285e427f2d9c29de3a39f6f6d48
- https://git.kernel.org/stable/c/f6324b4240cf0b26a84c33f68a1222d727ff4af2