KernelScan.io

HIGH

ksmbd DaclSize OOB

CVE-2026-68099

CVSS 8.3 / 10.0 KernelScan AI

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H

01

In the Linux kernel, the following vulnerability has been resolved: ksmbd: restore DACL size on check_add_overflow() to avoid malformed ACL check_add_overflow() unconditionally writes the truncated sum into *d even on overflow, per its contract in include/linux/overflow.h. The four check_add_overflow() guards in set_posix_acl_entries_dacl() and set_ntacl_dacl() break out of the ACE-building loops on overflow, but the truncated *size is then consumed downstream at the end of set_ntacl_dacl(): pndacl->size = cpu_to_le16(le16_to_cpu(pndacl->size) + size); This produces an on-wire NT ACL whose pndacl->size under-reports the bytes actually written by the preceding fill_ace_for_sid()/memcpy() calls, yielding a malformed ACL that can trigger out-of-bounds reads when re-parsed by clients or ksmbd itself. Restore *size to its pre-addition value on each overflow branch (via `*size -= ace_sz` / `size -= nt_ace_size`) so that after the break, *size once again holds the cumulative size of the successfully-written ACEs. The committed ACL is then truncated-but-self-consistent rather than malformed. The ksmbd DACL builders are the only check_add_overflow() sites found where an overflow path breaks out of a loop and the destination value is consumed afterward. The other nearby break-style cases either return -EINVAL on overflow (transport_ipc.c) or break without consuming the overflowed destination value afterward (buildid.c).

02

Engine v0.6.0

Risk summary

An authenticated SMB client connecting to a ksmbd server can trigger construction of a malformed NT ACL whose size field under-reports the actual bytes written. When this ACL is re-parsed by ksmbd or by SMB clients, the inconsistent size causes out-of-bounds reads that can leak kernel memory or crash the kernel. Any deployment running ksmbd with files that have many POSIX ACL entries is at risk.

Affectedfs/smb/server/smbacl.c (ksmbd)

Vulnerability analysis

When ksmbd builds NT ACLs from POSIX ACL entries, it accumulates the total size of each access control entry in a u16 variable using an overflow-checking helper. That helper unconditionally writes the truncated (wrapped) sum into the size variable even when overflow is detected, and the code breaks out of the loop without correcting the value. The truncated size is then used to set the ACL's on-wire size field, producing a malformed ACL that under-reports the bytes actually written. When this self-inconsistent ACL is later re-parsed by ksmbd or by an SMB client, the incorrect size causes out-of-bounds reads. The fix restores the size variable to its pre-addition value on each overflow branch, so the committed ACL is truncated but internally consistent. This is reachable from any authenticated SMB client with access to a share on a ksmbd server; no special kernel or administrative privileges are required beyond a valid SMB session.

03

BranchIntroducedFixed inPatch commit
6.126.12.846.12.1010bf38372821b
mainline—7.2—
6.66.6.1366.6.148f4fcd0c1a243
7.1—7.1.6bbf0a8e93120
7.07.0.27.1bc90144ce8bb
6.16.1.1756.1.1848f3a7a499a7d
6.186.18.256.18.42847ecd4eb3c1