ksmbd: restore DACL size on check_add_overflow() to avoid malformed ACL

Summary

CVECVE-2026-68099
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2026-08-10 13:19:54 UTC
Updated2026-08-10 13:19:54 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: ksmbd: restore DACL size on check_add_overflow() to avoid malformed ACL check_add_overflow() unconditionally writes the truncated sum into *d even on overflow, per its contract in include/linux/overflow.h. The four check_add_overflow() guards in set_posix_acl_entries_dacl() and set_ntacl_dacl() break out of the ACE-building loops on overflow, but the truncated *size is then consumed downstream at the end of set_ntacl_dacl(): pndacl->size = cpu_to_le16(le16_to_cpu(pndacl->size) + size); This produces an on-wire NT ACL whose pndacl->size under-reports the bytes actually written by the preceding fill_ace_for_sid()/memcpy() calls, yielding a malformed ACL that can trigger out-of-bounds reads when re-parsed by clients or ksmbd itself. Restore *size to its pre-addition value on each overflow branch (via `*size -= ace_sz` / `size -= nt_ace_size`) so that after the break, *size once again holds the cumulative size of the successfully-written ACEs. The committed ACL is then truncated-but-self-consistent rather than malformed. The ksmbd DACL builders are the only check_add_overflow() sites found where an overflow path breaks out of a loop and the destination value is consumed afterward. The other nearby break-style cases either return -EINVAL on overflow (transport_ipc.c) or break without consuming the overflowed destination value afterward (buildid.c).

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected 8d5729350b236896f51379588d9a690b7fafb8db f4fcd0c1a243d449307b887fafee23921e9db5ab git Not specified
CNA Linux Linux affected e1955a94b6f17f4b058afa955a6f187eb3ed7615 0bf38372821b1526f31538a7d9811844c55c7f38 git Not specified
CNA Linux Linux affected 5e7b8f3c539d69b2ed5f2408e2f75e68ce7eef43 847ecd4eb3c117c3d2f13f1e7ab506543aad8183 git Not specified
CNA Linux Linux affected 299f962c0b02d048fb45d248b4da493d03f3175d bc90144ce8bb7fcf05ad9417c7adb4e9509d9e13 git Not specified
CNA Linux Linux affected 299f962c0b02d048fb45d248b4da493d03f3175d bbf0a8e931204ecdab494a88d43b0a24a04285c5 git Not specified
CNA Linux Linux affected 41e53a773db6342ac9a689ee5ba635c31744c9f0 git Not specified
CNA Linux Linux affected ef7902be3f215b6bf7babe4dc9dd9a7d57dad7a7 git Not specified
CNA Linux Linux affected 6.6.136 6.6.148 semver Not specified
CNA Linux Linux affected 6.12.84 6.12.101 semver Not specified
CNA Linux Linux affected 6.18.25 6.18.42 semver Not specified
CNA Linux Linux affected 6.1.175 6.2 semver Not specified
CNA Linux Linux affected 7.0.2 7.1 semver Not specified
CNA Linux Linux affected 7.1 Not specified
CNA Linux Linux unaffected 7.1 semver Not specified
CNA Linux Linux unaffected 6.6.148 6.6.* semver Not specified
CNA Linux Linux unaffected 6.12.101 6.12.* semver Not specified
CNA Linux Linux unaffected 6.18.42 6.18.* semver Not specified
CNA Linux Linux unaffected 7.1.6 7.1.* semver Not specified
CNA Linux Linux unaffected 7.2-rc5 * original_commit_for_fix Not specified

References

ReferenceSourceLinkTags
git.kernel.org/stable/c/0bf38372821b1526f31538a7d9811844c55c7f38 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/bc90144ce8bb7fcf05ad9417c7adb4e9509d9e13 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/847ecd4eb3c117c3d2f13f1e7ab506543aad8183 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/bbf0a8e931204ecdab494a88d43b0a24a04285c5 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/f4fcd0c1a243d449307b887fafee23921e9db5ab 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report