HIGH Introduced in 5.15
ksmbd NtAcl OOB
CVE-2026-68100
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
KernelScan AI7.6HIGH
01Description
In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate num_subauth when copying ACE in set_ntacl_dacl set_ntacl_dacl() copies each ACE from the attacker-controlled stored security descriptor verbatim into the response DACL without checking sid.num_subauth. The ACE bytes (including an unchecked num_subauth) originate from an authenticated SMB2_SET_INFO(SecInfo=DACL) that is stored raw via ksmbd_vfs_set_sd_xattr(); parse_dacl() rejects a bad ACE with `break` rather than an error, so parse_sec_desc() still returns success and the malformed SD reaches the xattr intact. On a subsequent SMB2_QUERY_INFO(SecInfo=DACL) for an inode carrying a POSIX access ACL, build_sec_desc() -> set_ntacl_dacl() -> set_posix_acl_entries_dacl() walks the copied ACEs and reads ntace->sid.sub_auth[ntace->sid.num_subauth - 1] with num_subauth taken straight from the stored SD. Since sub_auth[] is fixed at SID_MAX_SUB_AUTHORITIES (15), a crafted num_subauth (e.g. 255) drives an out-of-bounds heap read of ~1 KB with an offset fully controlled by an authenticated client. The sibling functions already gate this field: parse_dacl() -- num_subauth == 0 || > SID_MAX_SUB_AUTHORITIES parse_sid() -- num_subauth > SID_MAX_SUB_AUTHORITIES smb_copy_sid() -- min_t(u8, num_subauth, SID_MAX_SUB_AUTHORITIES) set_ntacl_dacl() is the lone inconsistent path that omits the check. Add the same num_subauth validation in set_ntacl_dacl() before copying the ACE, matching the gate already enforced by parse_dacl().
02KernelScan AI Analysis
Risk summary
An authenticated SMB client can store a malformed security descriptor via SMB2_SET_INFO and later trigger an out-of-bounds heap read when the server reconstructs the DACL during SMB2_QUERY_INFO. The read offset and size are attacker-controlled, enabling kernel memory disclosure and potential denial of service. Any system running the ksmbd kernel SMB server with authenticated client access is affected.
Vulnerability analysis
The ksmbd SMB server stores raw security descriptor data submitted by an authenticated client without fully validating the SID sub-authority count field inside each ACE. When a later query asks the server to rebuild the DACL for an inode that also has a POSIX ACL, the server walks the stored ACEs and indexes into a fixed-size sub-authority array using the unchecked count, reading well past the array bounds on the heap. The fix adds the same validation that sibling parsing functions already enforce, skipping any ACE whose sub-authority count is zero or exceeds the maximum before it is copied into the response. The vulnerable path is reachable by any authenticated SMB client over the network; no special server-side privileges are required beyond a valid login session, and the ksmbd module must be loaded and configured to serve shares.
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| 6.1 | 5.15 | 6.1.184 | 26cb845e22a0 |
| 6.12 | 5.15 | 6.12.101 | fb3dc8e6da46 |
| 6.18 | 5.15 | 6.18.42 | b6d3cc6a5244 |
| 7.1 | 5.15 | 7.1.6 | 5acbd3012fd4 |
| mainline | 5.15 | 7.2 | 47f0b34f6bc9 |
| 6.6 | 5.15 | 6.6.148 | e31fada51437 |