KernelScan.io

HIGH Introduced in 5.15

ksmbd AceSize OOB

CVE-2026-68097

CVSS 8.8 / 10.0 NVD

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

KernelScan AI8.3HIGH

01

In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate ACE size against SID sub-authorities set_ntacl_dacl() validates sid.num_subauth before copying an ACE, but does not verify that the declared ACE size contains all sub-authorities described by that field. An undersized ACE can therefore be copied and later make the POSIX ACL deduplication walk inspect data beyond the copied ACE boundary. The existing initial bound check is also too small. It only ensures that the ACE size field is accessible before set_ntacl_dacl() reads sid.num_subauth farther into the input buffer. Require enough input for the fixed SID header before accessing num_subauth, reject ACEs smaller than that header, and skip ACEs whose declared size cannot contain the complete SID. This makes the validation consistent with the other ACE walk paths.

02

Engine v0.6.0

Risk summary

A network client authenticated to a ksmbd SMB server can send a malformed security descriptor with an undersized ACE whose declared SID sub-authority count exceeds the ACE boundary. The kernel copies the truncated ACE and later reads past it during POSIX ACL deduplication, leaking adjacent heap memory. Products exposing ksmbd on a reachable network are affected; air-gapped or non-SMB deployments are not.

Affectedfs/smb/server/smbacl.c (ksmbd)

Vulnerability analysis

When a client changes file permissions over SMB, the kernel server copies each permission entry from the client's message without checking that the entry's claimed size can actually hold all the account identifiers the entry says it contains. An attacker can therefore send an entry that claims to have many identifiers but provides too little data; the server copies the truncated entry, and later when it processes permissions internally it reads past the end of that entry into adjacent kernel memory. The corrected code now ensures the message contains the full identifier header before trusting the count, rejects entries smaller than that header, and skips entries whose size cannot fit all claimed identifiers. Any authenticated network client that can connect to the server's SMB share and modify file permissions can trigger this.

03

BranchIntroducedFixed inPatch commit
6.65.156.6.148b7cb5bf08554
6.125.156.12.10162d80d7c2d94
7.15.157.1.661fd3559199f
mainline5.157.2-rc55152c6d49e3f
6.185.156.18.42337022d9dfac