-

CVE-2026-68099

ksmbd: restore DACL size on check_add_overflow() to avoid malformed ACL

In the Linux kernel, the following vulnerability has been resolved:

ksmbd: restore DACL size on check_add_overflow() to avoid malformed ACL

check_add_overflow() unconditionally writes the truncated sum into *d
even on overflow, per its contract in include/linux/overflow.h.
The four check_add_overflow() guards in set_posix_acl_entries_dacl()
and set_ntacl_dacl() break out of the ACE-building loops on overflow,
but the truncated *size is then consumed downstream at the end of
set_ntacl_dacl():

    pndacl->size = cpu_to_le16(le16_to_cpu(pndacl->size) + size);

This produces an on-wire NT ACL whose pndacl->size under-reports the
bytes actually written by the preceding fill_ace_for_sid()/memcpy()
calls, yielding a malformed ACL that can trigger out-of-bounds reads
when re-parsed by clients or ksmbd itself.

Restore *size to its pre-addition value on each overflow branch (via
`*size -= ace_sz` / `size -= nt_ace_size`) so that after the break,
*size once again holds the cumulative size of the successfully-written
ACEs. The committed ACL is then truncated-but-self-consistent rather
than malformed.

The ksmbd DACL builders are the only check_add_overflow() sites found
where an overflow path breaks out of a loop and the destination value
is consumed afterward. The other nearby break-style cases either
return -EINVAL on overflow (transport_ipc.c) or break without
consuming the overflowed destination value afterward (buildid.c).
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 41e53a773db6342ac9a689ee5ba635c31744c9f0
Version < 8f3a7a499a7d9bb1c0f33fe78c4a4594d7e307f4
Status affected
Version 8d5729350b236896f51379588d9a690b7fafb8db
Version < f4fcd0c1a243d449307b887fafee23921e9db5ab
Status affected
Version e1955a94b6f17f4b058afa955a6f187eb3ed7615
Version < 0bf38372821b1526f31538a7d9811844c55c7f38
Status affected
Version 5e7b8f3c539d69b2ed5f2408e2f75e68ce7eef43
Version < 847ecd4eb3c117c3d2f13f1e7ab506543aad8183
Status affected
Version 299f962c0b02d048fb45d248b4da493d03f3175d
Version < bc90144ce8bb7fcf05ad9417c7adb4e9509d9e13
Status affected
Version 299f962c0b02d048fb45d248b4da493d03f3175d
Version < bbf0a8e931204ecdab494a88d43b0a24a04285c5
Status affected
Version ef7902be3f215b6bf7babe4dc9dd9a7d57dad7a7
Status affected
Version 6.1.175
Version < 6.1.184
Status affected
Version 6.6.136
Version < 6.6.148
Status affected
Version 6.12.84
Version < 6.12.101
Status affected
Version 6.18.25
Version < 6.18.42
Status affected
Version 7.0.2
Version < 7.1
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 7.1
Status affected
Version 0
Version < 7.1
Status unaffected
Version <= 6.1.*
Version 6.1.184
Status unaffected
Version <= 6.6.*
Version 6.6.148
Status unaffected
Version <= 6.12.*
Version 6.12.101
Status unaffected
Version <= 6.18.*
Version 6.18.42
Status unaffected
Version <= 7.1.*
Version 7.1.6
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.064
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/f4fcd0c1a243d449307b887fafee23921e9db5ab
https://git.kernel.org/stable/c/0bf38372821b1526f31538a7d9811844c55c7f38
https://git.kernel.org/stable/c/847ecd4eb3c117c3d2f13f1e7ab506543aad8183
https://git.kernel.org/stable/c/bc90144ce8bb7fcf05ad9417c7adb4e9509d9e13
https://git.kernel.org/stable/c/bbf0a8e931204ecdab494a88d43b0a24a04285c5
https://git.kernel.org/stable/c/8f3a7a499a7d9bb1c0f33fe78c4a4594d7e307f4