Executive brief
A vulnerability in the Linux kernel's SMB server (ksmbd) could allow an attacker to crash or slow down a system by exhausting its memory. By providing a specially crafted file with a large number of access control entries, an attacker can trigger a memory leak every time that file is accessed. This could eventually lead to a denial-of-service condition where the server becomes unresponsive.
Technical details
A memory leak exists in the ksmbd module of the Linux kernel within the 'set_posix_acl_entries_dacl' function in 'fs/smb/server/smbacl.c'. The vulnerability was introduced by a previous fix that added 'check_add_overflow()' guards to prevent u16 DACL size overflows but failed to free allocated 'smb_sid' structures when breaking out of the ACE-building loops. An attacker can exploit this by creating or providing a malformed file with a high number of POSIX ACL entries. Each request touching such a file's DACL triggers the overflow check and leaks 'struct smb_sid' allocations, providing a vector for kernel memory exhaustion (DoS). Patches have been released for various stable kernel branches including 6.1, 6.6, 6.12, and 6.18.
Affected products
- Linux Linux Kernel 6.1.175, 6.6.136, 6.12.84, 6.18.25
Timeline
- 2026-07-19: disclosed
- 2026-07-19: advisory
References
- https://git.kernel.org/stable/c/0e198f09cb2a554c04de0fea4e790f1250a943ca
- https://git.kernel.org/stable/c/519fb0a42ce5d7e46935577309fb282a5f2c6ea3
- https://git.kernel.org/stable/c/9d378e17c864da08c3a4df41dae92cfa6468b00a
- https://git.kernel.org/stable/c/af92ee994cc7f7e83a41c2025f32257a2f82a7ef
- https://git.kernel.org/stable/c/eced48cb08f07393a5ea770fdd1026452883c3ad