Executive brief
A vulnerability was identified in the Linux kernel's SMB client, which is used to connect to network file shares. The system failed to properly validate the length of security identifiers (SIDs) received from a network server. This could potentially allow a malicious or compromised server to cause a system crash or other unpredictable behavior on the connected Linux machine.
Technical details
A vulnerability in the `posix_info_sid_size()` function within the Linux kernel's SMB client (`fs/smb/client/smb2pdu.c` or `fs/cifs/smb2pdu.c`) allowed for an out-of-bounds read. The function attempted to read `sid[1]` to determine the subauthority count but only performed a boundary check for a single byte (`beg + 1 > end`). This allowed buffers with only one remaining byte to pass the check, leading to an invalid read of the second byte. An attacker controlling a malicious SMB server could provide truncated POSIX SIDs to trigger this behavior. The fix increases the boundary requirement to two bytes (`beg + 2 > end`) to ensure safe parsing.
Affected products
- Linux Linux Kernel 5.7 to 5.10.261, 5.15.212, 6.1.178, 6.6.145
Timeline
- 2026-06-28: other: Patch authored
- 2026-07-24: patched: Commits merged into stable branches
- 2026-07-25: disclosed: CVE published
References
- https://git.kernel.org/stable/c/0de5b8e76847f5de26f364a82c6602c4881c30da
- https://git.kernel.org/stable/c/171605aed68380c2fa75dff9b3a1ed427c50065b
- https://git.kernel.org/stable/c/4213c1208978483021d7d125c131de3985d38f61
- https://git.kernel.org/stable/c/427eb7eb46425fec845a43e861f3d6e2899cae59
- https://git.kernel.org/stable/c/46a84715a015cb48e1b9c219dc88c03d8a541ea4
- https://git.kernel.org/stable/c/7ad2bcf2441430bb2e918fb3ef9a90d775a6e422
- https://git.kernel.org/stable/c/86c5d470f5d42e61123b2f4b4f0b91f4eee5b980