-

CVE-2026-97561

smb: client: honor forceuid/forcegid when mapping SIDs to uid/gid

In the Linux kernel, the following vulnerability has been resolved:

smb: client: honor forceuid/forcegid when mapping SIDs to uid/gid

When the administrator mounts with forceuid or forcegid (uid=/gid=
mount options), they expect all files to appear owned by the specified
user/group.  However, several code paths unconditionally called
sid_to_id() to overwrite cf_uid/cf_gid with server-provided values,
ignoring the administrator's explicit override:

  - smb311_posix_info_to_fattr() (stat via POSIX extensions)
  - cifs_posix_to_fattr() (readdir via POSIX extensions)
  - parse_sec_desc() (CIFS ACL ownership mapping)

This allowed an untrusted server to dictate local file ownership even
when the mount was configured to force specific uid/gid values.

Fix all three call sites to check CIFS_MOUNT_OVERR_UID and
CIFS_MOUNT_OVERR_GID before calling sid_to_id(), following the
same pattern already used by cifs_unix_basic_to_fattr() for unix
extensions.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 9409ae58e0759d010b347e7b19ebc90ab5d4b98f
Version < e1b74f8f8c1d13190b09fe623b729d36b7ac22a8
Status affected
Version 9409ae58e0759d010b347e7b19ebc90ab5d4b98f
Version < 18a72975e9f35aadecc75b031f693f2d1f49308f
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 3.0
Status affected
Version 0
Version < 3.0
Status unaffected
Version <= 7.2.*
Version 7.2.7
Status unaffected
Version <= *
Version 7.3-rc3
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.19% 0.077
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/e1b74f8f8c1d13190b09fe623b729d36b7ac22a8
https://git.kernel.org/stable/c/18a72975e9f35aadecc75b031f693f2d1f49308f