-

CVE-2026-97564

smb: client: reject userspace cifs.idmap descriptions

In the Linux kernel, the following vulnerability has been resolved:

smb: client: reject userspace cifs.idmap descriptions

cifs.idmap key descriptions carry authority-bearing fields (owner and
group SIDs and uid/gid values in "os:"/"gs:"/"oi:"/"gi:" form) that the
cifs.idmap upcall helper treats as kernel-originating inputs.  Unlike
its sibling cifs.spnego, the cifs.idmap key type has no vet_description
hook, so userspace can create keys of this type through
request_key(2)/add_key(2) and supply those fields without CIFS origin.
A request_key(2) call with a non-NULL callout then drives a root
usermodehelper upcall (/sbin/request-key -> cifs.idmap) that consumes
the unvetted description in root context.

Only accept cifs.idmap descriptions while CIFS is using its private
root_cred to request the key.  id_to_sid()/sid_to_id() already run
under override_creds(root_cred), so the kernel-originated path is
unaffected.

This mirrors commit 3da1fdf4efbc ("smb: client: reject userspace
cifs.spnego descriptions"), which applied the same restriction to
cifs.spnego.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 4d79dba0e00749fa40de8ef13a9b85ce57a1603b
Version < f29c1ec0e7d8c887a91df3f93bb4617c0ac95c6a
Status affected
Version 4d79dba0e00749fa40de8ef13a9b85ce57a1603b
Version < 17c93bcd17755523c21abb22cbf2a41a6eb0caaf
Status affected
Version 4d79dba0e00749fa40de8ef13a9b85ce57a1603b
Version < e5964064e3fbe6325893408faff08ca33de0e2c3
Status affected
Version 4d79dba0e00749fa40de8ef13a9b85ce57a1603b
Version < 96751028c0d4dec785709ea3eb0ab38a4f2ded96
Status affected
Version 4d79dba0e00749fa40de8ef13a9b85ce57a1603b
Version < 1d3b24b16a0b013792e8f1e3ed060f0b46f537d1
Status affected
Version 4d79dba0e00749fa40de8ef13a9b85ce57a1603b
Version < d9d7eeb0cea5b55b82888f443622fd8d4ee064f3
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 3.0
Status affected
Version 0
Version < 3.0
Status unaffected
Version <= 6.1.*
Version 6.1.189
Status unaffected
Version <= 6.6.*
Version 6.6.158
Status unaffected
Version <= 6.12.*
Version 6.12.111
Status unaffected
Version <= 6.18.*
Version 6.18.53
Status unaffected
Version <= 7.2.*
Version 7.2.7
Status unaffected
Version <= *
Version 7.3-rc3
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.2% 0.088
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/e5964064e3fbe6325893408faff08ca33de0e2c3
https://git.kernel.org/stable/c/96751028c0d4dec785709ea3eb0ab38a4f2ded96
https://git.kernel.org/stable/c/1d3b24b16a0b013792e8f1e3ed060f0b46f537d1
https://git.kernel.org/stable/c/d9d7eeb0cea5b55b82888f443622fd8d4ee064f3
https://git.kernel.org/stable/c/17c93bcd17755523c21abb22cbf2a41a6eb0caaf
https://git.kernel.org/stable/c/f29c1ec0e7d8c887a91df3f93bb4617c0ac95c6a