Executive brief
A vulnerability was identified in the Linux kernel's ksmbd component, which provides SMB file sharing services. The issue occurs when a new file or directory inherits security permissions from its parent folder; specifically, the system failed to properly validate security identifiers (SIDs). This could potentially lead to system instability or unauthorized access if a specially crafted security descriptor is processed.
Technical details
A vulnerability in the ksmbd SMB server in the Linux kernel was addressed by improving validation of Security Identifiers (SIDs) during Access Control List (ACL) inheritance. Specifically, the `smb_inherit_dacl` function lacked sufficient bounds checking when retrieving Owner and Group SIDs from a parent directory's NT Security Descriptor (smb_ntsd). An attacker could potentially exploit this by providing a malformed security descriptor that triggers out-of-bounds access or integer overflows during the inheritance process. The fix introduces the `smb_validate_ntsd_sid()` helper to ensure SID offsets and sub-authority counts remain within the allocated buffer limits. This affects Linux kernel versions prior to 6.12.92, 6.18.34, and 7.0.11.
Affected products
- Linux Linux Kernel 6.12.92, 6.18.34, 7.0.11, 7.1
Timeline
- 2026-05-19: other: Patch authored
- 2026-07-19: disclosed: CVE published
- 2026-07-19: advisory