Description
In the Linux kernel, the following vulnerability has been resolved:

ksmbd: bound smb_check_perm_dacl() ACE walks by DACL size

smb_check_perm_dacl() validates that the DACL fits inside the NT
security descriptor, but then bounds its two ACE walks by the
remaining NTSD length (acl_size) rather than the DACL's declared
size (pdacl_size).

When pdacl->size is smaller than the trailing NTSD buffer, bytes
after the declared DACL boundary - still inside the stored security
descriptor - are parsed as ACEs during access checks. A crafted
DACL can place an access-granting ACE beyond pdacl->size, and the
current code accepts it during SMB2_CREATE access validation, while
parse_dacl() and smb_inherit_dacl() stop at pdacl_size.

Bound both ACE walks by pdacl_size to match the DACL boundary
semantics used elsewhere in the server.

Validation:
- semantic KUnit harness shows the post-boundary ACE is selected
before the fix and rejected (EACCES) after it
- linux master (7.2-rc6), x86_64
Published: 2026-09-17
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation via Unauthorized SMB Access
Action: Patch Immediately
AI Analysis

Impact

The Linux kernel’s SMB server accidentally parses security descriptor data after the declared DACL boundary. A crafted DACL can insert an ACE that grants access beyond the proper size, and the SMB2_CREATE access validation accepts this ACE while other parsing functions do not. This flaw allows an attacker to gain unauthorized SMB access and potentially elevate privileges on the host. The weakness is a failure of proper bounds checking and input validation, leading to an authorization bypass.

Affected Systems

The vulnerability affects Linux systems running the default kernel implementation. The patch is available in the Linux kernel master branch from commit 7.2-rc6 onward on x86_64 architectures. Linux versions that did not incorporate this commit remain vulnerable.

Risk and Exploitability

The CVSS score of 8.1 indicates high severity, and the EPSS score of less than 1% shows a low current exploitation probability. The report is not listed in CISA’s KEV catalog. Attackers can exploit this flaw remotely by sending a specially crafted SMB2 request to an exposed SMB server. The vulnerability is specific to SMB server access checks performed by the kernel’s ksmbd component and requires network connectivity to the target.

Generated by OpenCVE AI on September 20, 2026 at 01:56 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a release that includes the patch from commit 7.2-rc6 or later.
  • Configure firewall rules or network segmentation to restrict or block SMB traffic to the vulnerable host.
  • Audit all SMB servers for unnecessary service exposure and disable SMB services that are not required.

Generated by OpenCVE AI on September 20, 2026 at 01:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sun, 20 Sep 2026 02:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-122
CWE-125

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: ksmbd: bound smb_check_perm_dacl() ACE walks by DACL size smb_check_perm_dacl() validates that the DACL fits inside the NT security descriptor, but then bounds its two ACE walks by the remaining NTSD length (acl_size) rather than the DACL's declared size (pdacl_size). When pdacl->size is smaller than the trailing NTSD buffer, bytes after the declared DACL boundary - still inside the stored security descriptor - are parsed as ACEs during access checks. A crafted DACL can place an access-granting ACE beyond pdacl->size, and the current code accepts it during SMB2_CREATE access validation, while parse_dacl() and smb_inherit_dacl() stop at pdacl_size. Bound both ACE walks by pdacl_size to match the DACL boundary semantics used elsewhere in the server. Validation: - semantic KUnit harness shows the post-boundary ACE is selected before the fix and rejected (EACCES) after it - linux master (7.2-rc6), x86_64
Title ksmbd: bound smb_check_perm_dacl() ACE walks by DACL size
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:53:28.059Z

Reserved: 2026-09-11T19:38:34.789Z

Link: CVE-2026-90153

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:08.370

Modified: 2026-09-18T18:17:44.427

Link: CVE-2026-90153

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T02:00:13Z

Weaknesses