Impact
The Linux kernel’s SMB server accidentally parses security descriptor data after the declared DACL boundary. A crafted DACL can insert an ACE that grants access beyond the proper size, and the SMB2_CREATE access validation accepts this ACE while other parsing functions do not. This flaw allows an attacker to gain unauthorized SMB access and potentially elevate privileges on the host. The weakness is a failure of proper bounds checking and input validation, leading to an authorization bypass.
Affected Systems
The vulnerability affects Linux systems running the default kernel implementation. The patch is available in the Linux kernel master branch from commit 7.2-rc6 onward on x86_64 architectures. Linux versions that did not incorporate this commit remain vulnerable.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity, and the EPSS score of less than 1% shows a low current exploitation probability. The report is not listed in CISA’s KEV catalog. Attackers can exploit this flaw remotely by sending a specially crafted SMB2 request to an exposed SMB server. The vulnerability is specific to SMB server access checks performed by the kernel’s ksmbd component and requires network connectivity to the target.
OpenCVE Enrichment
Debian DLA
Debian DSA