{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-93785","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-18T17:59:28.788Z","datePublished":"2026-09-24T16:02:18.964Z","dateUpdated":"2026-10-03T10:57:20.267Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-10-03T10:57:20.267Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ncifs: validate idmap key payload length\n\nThe cifs.idmap key type stores its payload length in key->datalen, which\nis limited to U16_MAX.  Accepting a larger key payload truncates the\nrecorded length and can make later users interpret the payload using\ninconsistent bounds.\n\nReject oversized preparsed payloads before allocating or copying them.\nThis keeps key->datalen consistent with the stored data for both inline\nand separately allocated idmap payloads."}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/smb/client/cifsacl.c"],"versions":[{"version":"21fed0d5b763b94a7d1568c27d0cce892ab8d43e","lessThan":"eeac976b74b4f697cfc517187b7cbfd72652dbbc","status":"affected","versionType":"git"},{"version":"21fed0d5b763b94a7d1568c27d0cce892ab8d43e","lessThan":"125b05ac8ca8758950e4369c1542d57a162f504c","status":"affected","versionType":"git"},{"version":"21fed0d5b763b94a7d1568c27d0cce892ab8d43e","lessThan":"945f6cde6bcf8f08f6fa5df8882b1b9582e55efa","status":"affected","versionType":"git"},{"version":"21fed0d5b763b94a7d1568c27d0cce892ab8d43e","lessThan":"3a4a34a732e8a08309eed0a74314dbd9f2f1c972","status":"affected","versionType":"git"},{"version":"21fed0d5b763b94a7d1568c27d0cce892ab8d43e","lessThan":"6cfeef221ac00d63c07f6122f58e6159bde69ca0","status":"affected","versionType":"git"},{"version":"21fed0d5b763b94a7d1568c27d0cce892ab8d43e","lessThan":"8b12f65d7caf16d124098cb4895a203367d35b57","status":"affected","versionType":"git"},{"version":"21fed0d5b763b94a7d1568c27d0cce892ab8d43e","lessThan":"455488cd5054bcc59db40fa1cc2c004031a5b2a5","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/smb/client/cifsacl.c"],"versions":[{"version":"3.2","status":"affected"},{"version":"0","lessThan":"3.2","status":"unaffected","versionType":"semver"},{"version":"5.10.271","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.222","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.189","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.158","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.111","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.53","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.2","versionEndExcluding":"5.10.271"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.2","versionEndExcluding":"5.15.222"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.2","versionEndExcluding":"6.1.189"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.2","versionEndExcluding":"6.6.158"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.2","versionEndExcluding":"6.12.111"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.2","versionEndExcluding":"6.18.53"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.2","versionEndExcluding":"7.2"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/eeac976b74b4f697cfc517187b7cbfd72652dbbc"},{"url":"https://git.kernel.org/stable/c/125b05ac8ca8758950e4369c1542d57a162f504c"},{"url":"https://git.kernel.org/stable/c/945f6cde6bcf8f08f6fa5df8882b1b9582e55efa"},{"url":"https://git.kernel.org/stable/c/3a4a34a732e8a08309eed0a74314dbd9f2f1c972"},{"url":"https://git.kernel.org/stable/c/6cfeef221ac00d63c07f6122f58e6159bde69ca0"},{"url":"https://git.kernel.org/stable/c/8b12f65d7caf16d124098cb4895a203367d35b57"},{"url":"https://git.kernel.org/stable/c/455488cd5054bcc59db40fa1cc2c004031a5b2a5"}],"title":"cifs: validate idmap key payload length","x_generator":{"engine":"bippy-1.2.0"}}}}