HIGH Introduced in 5.15
ksmbd AceSize OOB
CVE-2026-68097
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
KernelScan AI8.3HIGH
01Description
In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate ACE size against SID sub-authorities set_ntacl_dacl() validates sid.num_subauth before copying an ACE, but does not verify that the declared ACE size contains all sub-authorities described by that field. An undersized ACE can therefore be copied and later make the POSIX ACL deduplication walk inspect data beyond the copied ACE boundary. The existing initial bound check is also too small. It only ensures that the ACE size field is accessible before set_ntacl_dacl() reads sid.num_subauth farther into the input buffer. Require enough input for the fixed SID header before accessing num_subauth, reject ACEs smaller than that header, and skip ACEs whose declared size cannot contain the complete SID. This makes the validation consistent with the other ACE walk paths.
02KernelScan AI Analysis
Risk summary
A network client authenticated to a ksmbd SMB server can send a malformed security descriptor with an undersized ACE whose declared SID sub-authority count exceeds the ACE boundary. The kernel copies the truncated ACE and later reads past it during POSIX ACL deduplication, leaking adjacent heap memory. Products exposing ksmbd on a reachable network are affected; air-gapped or non-SMB deployments are not.
Vulnerability analysis
When a client changes file permissions over SMB, the kernel server copies each permission entry from the client's message without checking that the entry's claimed size can actually hold all the account identifiers the entry says it contains. An attacker can therefore send an entry that claims to have many identifiers but provides too little data; the server copies the truncated entry, and later when it processes permissions internally it reads past the end of that entry into adjacent kernel memory. The corrected code now ensures the message contains the full identifier header before trusting the count, rejects entries smaller than that header, and skips entries whose size cannot fit all claimed identifiers. Any authenticated network client that can connect to the server's SMB share and modify file permissions can trigger this.
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| 6.6 | 5.15 | 6.6.148 | b7cb5bf08554 |
| 6.12 | 5.15 | 6.12.101 | 62d80d7c2d94 |
| 7.1 | 5.15 | 7.1.6 | 61fd3559199f |
| mainline | 5.15 | 7.2-rc5 | 5152c6d49e3f |
| 6.18 | 5.15 | 6.18.42 | 337022d9dfac |