KernelScan.io

HIGH Introduced in 3.2

cifs IdmapKey Overflow

CVE-2026-93785

CVSS 7.5 / 10.0 KernelScan AI

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

01

In the Linux kernel, the following vulnerability has been resolved: cifs: validate idmap key payload length The cifs.idmap key type stores its payload length in key->datalen, which is limited to U16_MAX. Accepting a larger key payload truncates the recorded length and can make later users interpret the payload using inconsistent bounds. Reject oversized preparsed payloads before allocating or copying them. This keeps key->datalen consistent with the stored data for both inline and separately allocated idmap payloads.

02

Engine v0.6.0

Risk summary

A local unprivileged user can trigger an integer truncation in the CIFS idmap key handling by supplying an oversized key payload, creating inconsistent bounds that may lead to kernel memory corruption. The vulnerability requires only that the CIFS module be present and a local user account, making it relevant for multi-tenant and container environments.

Affectedfs/smb/client/cifsacl.c (cifs/smb client)

Vulnerability analysis

The CIFS idmap key type stores its payload length in a field limited to 65535, but the key instantiation function accepted payloads larger than that limit without checking. When an oversized payload is supplied, the recorded length is silently truncated, leaving the stored data and its recorded size inconsistent; later code that reads the idmap key may then interpret the payload using the wrong bounds and access memory outside the intended region. The fix rejects any payload whose length exceeds the maximum representable value before any data is allocated or copied, keeping the recorded length consistent with the actual stored data. The vulnerability is reachable from a local unprivileged process through the standard keyring syscall interface whenever the CIFS module is present; no network access, special capabilities, or particular hardware are required.

03

BranchIntroducedFixed inPatch commit
6.123.26.12.1116cfeef221ac0
6.183.26.18.538b12f65d7caf
mainline3.27.2455488cd5054