KernelScan.io

HIGH

ksmbd DaclCheck Bypass

CVE-2026-90153

CVSS 8.1 / 10.0 NVD

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

KernelScan AI8.1HIGH

01

In the Linux kernel, the following vulnerability has been resolved: ksmbd: bound smb_check_perm_dacl() ACE walks by DACL size smb_check_perm_dacl() validates that the DACL fits inside the NT security descriptor, but then bounds its two ACE walks by the remaining NTSD length (acl_size) rather than the DACL's declared size (pdacl_size). When pdacl->size is smaller than the trailing NTSD buffer, bytes after the declared DACL boundary - still inside the stored security descriptor - are parsed as ACEs during access checks. A crafted DACL can place an access-granting ACE beyond pdacl->size, and the current code accepts it during SMB2_CREATE access validation, while parse_dacl() and smb_inherit_dacl() stop at pdacl_size. Bound both ACE walks by pdacl_size to match the DACL boundary semantics used elsewhere in the server. Validation: - semantic KUnit harness shows the post-boundary ACE is selected before the fix and rejected (EACCES) after it - linux master (7.2-rc6), x86_64

02

Engine v0.6.0

Risk summary

An authenticated SMB client can craft a malformed security descriptor on a file such that the ksmbd access-check function reads Access Control Entries beyond the DACL's declared boundary, finding a hidden access-granting ACE and bypassing intended deny permissions. This allows unauthorized read and write access to files on the affected share. The vulnerability requires network access to the SMB server and authenticated user credentials with at least DACL-write permission on a target file.

Affectedfs/smb/server/smbacl.c (ksmbd)

Vulnerability analysis

The ksmbd in-kernel SMB server checks whether a client is allowed to access a file by scanning the file's access rules. The server uses the wrong size limit during this scan, so it keeps reading past the end of the intended rule list and treats trailing bytes as valid access rules. An attacker can craft a file's permission metadata that looks restrictive to administrators but hides an extra access-granting rule in this trailing region. The access check accepts the hidden rule, while other server logic correctly stops at the boundary and never sees it. This allows an authenticated network client to bypass intended file permissions and gain unauthorized read or write access. The fix makes the access check respect the same boundary used elsewhere in the server.

03

BranchIntroducedFixed inPatch commit
5.155.15.625.16a2051ffe452a
5.185.18.185.19a29f57a14c93
5.195.19.25.20a4a307d14932
6.12—6.12.11079decd88dd3f
6.18—6.18.52—
7.2—7.2.6—
mainline—7.3-rc1—
6.6—6.6.1578e4f75e979c1