-

CVE-2026-97554

smb: client: avoid using uninitialized SIDs in cifs_posix_to_fattr()

In the Linux kernel, the following vulnerability has been resolved:

smb: client: avoid using uninitialized SIDs in cifs_posix_to_fattr()

cifs_posix_to_fattr() ignores the return value of posix_info_parse().
When a malformed POSIX directory entry is encountered (e.g. invalid
SID lengths from an untrusted server), posix_info_parse() returns -1
without populating the 'parsed' struct.  The uninitialized stack
memory in parsed.owner and parsed.group is then passed to
sid_to_id(), which processes the garbage bytes and passes them to
request_key() to construct a SID string, potentially leaking kernel
stack contents to the userspace idmap daemon.

Fix this by checking the return value and skipping the SID-to-id
mapping when parsing fails.  The remaining fattr fields (timestamps,
mode, etc.) are populated directly from the 'info' pointer so they
are unaffected.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 9934430e2178d5164eb1ac91a9b092f9e7e64745
Version < c9a8b60ce140a68d172452f418137fc7ddbae7db
Status affected
Version 9934430e2178d5164eb1ac91a9b092f9e7e64745
Version < da6e25842431982d5a53cf00d925b98c690f4467
Status affected
Version dd80b98bdf0a4b3206739f3513b0518f27a7b4ef
Status affected
Version d8e39c11f66125f49de55537a6efc8ecadf4a0f7
Status affected
Version 5.8.17
Version < 5.9
Status affected
Version 5.9.2
Version < 5.10
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 5.10
Status affected
Version 0
Version < 5.10
Status unaffected
Version <= 7.2.*
Version 7.2.7
Status unaffected
Version <= *
Version 7.3-rc3
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.19% 0.077
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/c9a8b60ce140a68d172452f418137fc7ddbae7db
https://git.kernel.org/stable/c/da6e25842431982d5a53cf00d925b98c690f4467