HIGH Introduced in 3.2
cifs IdmapKey Overflow
CVE-2026-93785
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
01Description
In the Linux kernel, the following vulnerability has been resolved: cifs: validate idmap key payload length The cifs.idmap key type stores its payload length in key->datalen, which is limited to U16_MAX. Accepting a larger key payload truncates the recorded length and can make later users interpret the payload using inconsistent bounds. Reject oversized preparsed payloads before allocating or copying them. This keeps key->datalen consistent with the stored data for both inline and separately allocated idmap payloads.
02KernelScan AI Analysis
Risk summary
A local unprivileged user can trigger an integer truncation in the CIFS idmap key handling by supplying an oversized key payload, creating inconsistent bounds that may lead to kernel memory corruption. The vulnerability requires only that the CIFS module be present and a local user account, making it relevant for multi-tenant and container environments.
Vulnerability analysis
The CIFS idmap key type stores its payload length in a field limited to 65535, but the key instantiation function accepted payloads larger than that limit without checking. When an oversized payload is supplied, the recorded length is silently truncated, leaving the stored data and its recorded size inconsistent; later code that reads the idmap key may then interpret the payload using the wrong bounds and access memory outside the intended region. The fix rejects any payload whose length exceeds the maximum representable value before any data is allocated or copied, keeping the recorded length consistent with the actual stored data. The vulnerability is reachable from a local unprivileged process through the standard keyring syscall interface whenever the CIFS module is present; no network access, special capabilities, or particular hardware are required.
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| 6.12 | 3.2 | 6.12.111 | 6cfeef221ac0 |
| 6.18 | 3.2 | 6.18.53 | 8b12f65d7caf |
| mainline | 3.2 | 7.2 | 455488cd5054 |