{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-97554","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-24T16:01:01.154Z","datePublished":"2026-09-25T10:21:45.851Z","dateUpdated":"2026-09-28T05:31:06.770Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-28T05:31:06.770Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: avoid using uninitialized SIDs in cifs_posix_to_fattr()\n\ncifs_posix_to_fattr() ignores the return value of posix_info_parse().\nWhen a malformed POSIX directory entry is encountered (e.g. invalid\nSID lengths from an untrusted server), posix_info_parse() returns -1\nwithout populating the 'parsed' struct.  The uninitialized stack\nmemory in parsed.owner and parsed.group is then passed to\nsid_to_id(), which processes the garbage bytes and passes them to\nrequest_key() to construct a SID string, potentially leaking kernel\nstack contents to the userspace idmap daemon.\n\nFix this by checking the return value and skipping the SID-to-id\nmapping when parsing fails.  The remaining fattr fields (timestamps,\nmode, etc.) are populated directly from the 'info' pointer so they\nare unaffected."}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/smb/client/readdir.c"],"versions":[{"version":"9934430e2178d5164eb1ac91a9b092f9e7e64745","lessThan":"c9a8b60ce140a68d172452f418137fc7ddbae7db","status":"affected","versionType":"git"},{"version":"9934430e2178d5164eb1ac91a9b092f9e7e64745","lessThan":"da6e25842431982d5a53cf00d925b98c690f4467","status":"affected","versionType":"git"},{"version":"dd80b98bdf0a4b3206739f3513b0518f27a7b4ef","status":"affected","versionType":"git"},{"version":"d8e39c11f66125f49de55537a6efc8ecadf4a0f7","status":"affected","versionType":"git"},{"version":"5.8.17","lessThan":"5.9","status":"affected","versionType":"semver"},{"version":"5.9.2","lessThan":"5.10","status":"affected","versionType":"semver"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/smb/client/readdir.c"],"versions":[{"version":"5.10","status":"affected"},{"version":"0","lessThan":"5.10","status":"unaffected","versionType":"semver"},{"version":"7.2.7","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc3","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.10","versionEndExcluding":"7.2.7"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.10","versionEndExcluding":"7.3-rc3"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.8.17"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.9.2"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/c9a8b60ce140a68d172452f418137fc7ddbae7db"},{"url":"https://git.kernel.org/stable/c/da6e25842431982d5a53cf00d925b98c690f4467"}],"title":"smb: client: avoid using uninitialized SIDs in cifs_posix_to_fattr()","x_generator":{"engine":"bippy-1.2.0"}}}}