PT-2026-61226 · Linux · Linux
CVE-2026-63909
·
Published
2026-07-19
·
Updated
2026-07-19
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H |
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: OOB read regression in smb check perm dacl() ACE-walk loops
Commit d07b26f39246 ("ksmbd: require minimum ACE size in
smb check perm dacl()") introduced a transposed bounds check:
if (offsetof(struct smb ace, sid) + aces size < CIFS SID BASE SIZE)
Since offsetof(..sid) is 8 and CIFS SID BASE SIZE is 8, this evaluates
to
aces size < 0. Because aces size is always non-negative, this
check becomes dead code and never breaks the loop.Worse, that commit removed the old 4-byte guard, meaning the loop now
reads
ace->size (offset 2) even when aces size is 0-3 bytes. This
re-opens a 2-byte heap out-of-bounds (OOB) read past the pntsd allocation
during subsequent SMB2 CREATE operations.Fix this by properly transposing the comparison to require at least
16 bytes (8-byte offset + 8-byte SID base), matching the correct form
used in smb inherit dacl().
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux