{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-90153","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.789Z","datePublished":"2026-09-17T16:06:46.296Z","dateUpdated":"2026-09-18T17:53:28.059Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-18T17:53:28.059Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: bound smb_check_perm_dacl() ACE walks by DACL size\n\nsmb_check_perm_dacl() validates that the DACL fits inside the NT\nsecurity descriptor, but then bounds its two ACE walks by the\nremaining NTSD length (acl_size) rather than the DACL's declared\nsize (pdacl_size).\n\nWhen pdacl->size is smaller than the trailing NTSD buffer, bytes\nafter the declared DACL boundary - still inside the stored security\ndescriptor - are parsed as ACEs during access checks.  A crafted\nDACL can place an access-granting ACE beyond pdacl->size, and the\ncurrent code accepts it during SMB2_CREATE access validation, while\nparse_dacl() and smb_inherit_dacl() stop at pdacl_size.\n\nBound both ACE walks by pdacl_size to match the DACL boundary\nsemantics used elsewhere in the server.\n\nValidation:\n- semantic KUnit harness shows the post-boundary ACE is selected\n  before the fix and rejected (EACCES) after it\n- linux master (7.2-rc6), x86_64"}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","baseScore":8.1,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:N - The crafted NTSD is carried in SMB2_SET_INFO (SMB2_O_INFO_SECURITY) or an SMB2_CREATE SMB2_CREATE_SD_BUFFER context; set_info_sec()/ksmbd_vfs_set_sd_xattr() store that buffer, and a later SMB2_CREATE in smb2_open() loads it into smb_check_perm_dacl() from ksmbd_conn_handler_loop() on TCP/445.\nAC:L - The attacker sets pdacl->size smaller than the NTSD tail, inflates num_aces, and places an ACCESS_ALLOWED ACE after the declared DACL; smb_check_perm_dacl() then walks those bytes on the next SMB2_CREATE with no race or attacker-uncontrollable layout.\nPR:L - __handle_ksmbd_work() requires check_user_session()/get_ksmbd_tcon() before smb2_open()/smb2_set_info(); planting the NTSD needs FILE_WRITE_DAC/FILE_WRITE_OWNER in smb2_set_info_sec() or create rights for SMB2_CREATE_SD_BUFFER on an acl-xattr share, not a pre-auth path.\nUI:N - The attacker alone sends the SMB2_SET_INFO or SMB2_CREATE SD_BUFFER that stores the NTSD and the SMB2_CREATE that calls smb_check_perm_dacl(); no victim mount, open, or other interactive step is required.\nS:U - smb_check_perm_dacl() only mis-evaluates the stored DACL for ksmbd file opens; the resulting access grant stays inside the kernel SMB server and does not cross a VM, IOMMU, or sandbox boundary.\nC:H - The SID-matching ACE walk in smb_check_perm_dacl() can select a post-pdacl->size ACCESS_ALLOWED ACE for the caller or Everyone and apply its access_req, so SMB2_CREATE is authorized for FILE_READ_DATA that the declared DACL would have denied with -EACCES.\nI:H - The same extra ACE supplies attacker-controlled ace->access_req; ACCESS_ALLOWED with FILE_WRITE_DATA/GENERIC_ALL makes smb_check_perm_dacl() accept a write SMB2_CREATE that parse_dacl() and smb_inherit_dacl() never grant from the bounded DACL.\nA:N - Both walks stay inside the NTSD (acl_size from pntsd_size); the bug only returns success instead of -EACCES and does not oops, panic, hang, or corrupt memory."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/smb/server/smbacl.c"],"versions":[{"version":"8f0541186e9ad1b62accc9519cc2b7a7240272a7","lessThan":"a2051ffe452afad52f580b85a3fd8851933b1e7c","status":"affected","versionType":"git"},{"version":"8f0541186e9ad1b62accc9519cc2b7a7240272a7","lessThan":"a29f57a14c939586d84d7fd6a029bd1fd170098f","status":"affected","versionType":"git"},{"version":"8f0541186e9ad1b62accc9519cc2b7a7240272a7","lessThan":"a4a307d149327dad5fb25187e1b03cebd1b04de6","status":"affected","versionType":"git"},{"version":"8f0541186e9ad1b62accc9519cc2b7a7240272a7","lessThan":"8e4f75e979c1d9a51b0a48ac33d0cfd5f039ec67","status":"affected","versionType":"git"},{"version":"8f0541186e9ad1b62accc9519cc2b7a7240272a7","lessThan":"79decd88dd3f0d42e7fb0689b1a7853bfa302459","status":"affected","versionType":"git"},{"version":"cb69d4d6f709f87c94afa28ae64c501576692171","status":"affected","versionType":"git"},{"version":"6e8f4abf584253cbaa596ea4ad13110cf61cd4c9","status":"affected","versionType":"git"},{"version":"8e33102309bd6839b2e2e158f93a7b378cb4655d","status":"affected","versionType":"git"},{"version":"5.15.62","lessThan":"5.16","status":"affected","versionType":"semver"},{"version":"5.18.18","lessThan":"5.19","status":"affected","versionType":"semver"},{"version":"5.19.2","lessThan":"5.20","status":"affected","versionType":"semver"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/smb/server/smbacl.c"],"versions":[{"version":"6.0","status":"affected"},{"version":"0","lessThan":"6.0","status":"unaffected","versionType":"semver"},{"version":"6.6.157","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.110","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.52","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.6","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.0","versionEndExcluding":"6.6.157"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.0","versionEndExcluding":"6.12.110"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.0","versionEndExcluding":"6.18.52"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.0","versionEndExcluding":"7.2.6"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.0","versionEndExcluding":"7.3-rc1"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.15.62"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.18.18"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.19.2"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/a2051ffe452afad52f580b85a3fd8851933b1e7c"},{"url":"https://git.kernel.org/stable/c/a29f57a14c939586d84d7fd6a029bd1fd170098f"},{"url":"https://git.kernel.org/stable/c/a4a307d149327dad5fb25187e1b03cebd1b04de6"},{"url":"https://git.kernel.org/stable/c/8e4f75e979c1d9a51b0a48ac33d0cfd5f039ec67"},{"url":"https://git.kernel.org/stable/c/79decd88dd3f0d42e7fb0689b1a7853bfa302459"}],"title":"ksmbd: bound smb_check_perm_dacl() ACE walks by DACL size","x_generator":{"engine":"bippy-1.2.0"}}}}