{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-31706", "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67", "state": "PUBLISHED", "assignerShortName": "Linux", "dateReserved": "2026-03-09T15:48:24.132Z", "datePublished": "2026-05-01T13:56:04.552Z", "dateUpdated": "2026-08-05T12:24:40.999Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67", "shortName": "Linux", "dateUpdated": "2026-08-05T12:24:40.999Z" }, "descriptions": [ { "lang": "en", "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: validate num_aces and harden ACE walk in smb_inherit_dacl()\n\nsmb_inherit_dacl() trusts the on-disk num_aces value from the parent\ndirectory's DACL xattr and uses it to size a heap allocation:\n\n aces_base = kmalloc(sizeof(struct smb_ace) * num_aces * 2, ...);\n\nnum_aces is a u16 read from le16_to_cpu(parent_pdacl->num_aces)\nwithout checking that it is consistent with the declared pdacl_size.\nAn authenticated client whose parent directory's security.NTACL is\ntampered (e.g. via offline xattr corruption or a concurrent path that\nbypasses parse_dacl()) can present num_aces = 65535 with minimal\nactual ACE data. This causes a ~8 MB allocation (not kzalloc, so\nuninitialized) that the subsequent loop only partially populates, and\nmay also overflow the three-way size_t multiply on 32-bit kernels.\n\nAdditionally, the ACE walk loop uses the weaker\noffsetof(struct smb_ace, access_req) minimum size check rather than\nthe minimum valid on-wire ACE size, and does not reject ACEs whose\ndeclared size is below the minimum.\n\nReproduced on UML + KASAN + LOCKDEP against the real ksmbd code path.\nA legitimate mount.cifs client creates a parent directory over SMB\n(ksmbd writes a valid security.NTACL xattr), then the NTACL blob on\nthe backing filesystem is rewritten to set num_aces = 0xFFFF while\nkeeping the posix_acl_hash bytes intact so ksmbd_vfs_get_sd_xattr()'s\nhash check still passes. A subsequent SMB2 CREATE of a child under\nthat parent drives smb2_open() into smb_inherit_dacl() (share has\n\"vfs objects = acl_xattr\" set), which fails the page allocator:\n\n WARNING: mm/page_alloc.c:5226 at __alloc_frozen_pages_noprof+0x46c/0x9c0\n Workqueue: ksmbd-io handle_ksmbd_work\n __alloc_frozen_pages_noprof+0x46c/0x9c0\n ___kmalloc_large_node+0x68/0x130\n __kmalloc_large_node_noprof+0x24/0x70\n __kmalloc_noprof+0x4c9/0x690\n smb_inherit_dacl+0x394/0x2430\n smb2_open+0x595d/0xabe0\n handle_ksmbd_work+0x3d3/0x1140\n\nWith the patch applied the added guard rejects the tampered value\nwith -EINVAL before any large allocation runs, smb2_open() falls back\nto smb2_create_sd_buffer(), and the child is created with a default\nSD. No warning, no splat.\n\nFix by:\n\n 1. Validating num_aces against pdacl_size using the same formula\n applied in parse_dacl().\n\n 2. Replacing the raw kmalloc(sizeof * num_aces * 2) with\n kmalloc_array(num_aces * 2, sizeof(...)) for overflow-safe\n allocation.\n\n 3. Tightening the per-ACE loop guard to require the minimum valid\n ACE size (offsetof(smb_ace, sid) + CIFS_SID_BASE_SIZE) and\n rejecting under-sized ACEs, matching the hardening in\n smb_check_perm_dacl() and parse_dacl().\n\nv1 -> v2:\n - Replace the synthetic test-module splat in the changelog with a\n real-path UML + KASAN reproduction driven through mount.cifs and\n SMB2 CREATE; Namjae flagged the kcifs3_test_inherit_dacl_old name\n in v1 since it does not exist in ksmbd.\n - Drop the commit-hash citation from the code comment per Namjae's\n review; keep the parse_dacl() pointer." } ], "metrics": [ { "cvssV3_1": { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 8.8, "baseSeverity": "HIGH" }, "scenarios": [ { "lang": "en", "value": "AV:N - ksmbd processes SMB2 CREATE requests over TCP/445, and the vulnerable `smb_inherit_dacl()` path is reached remotely through the in-kernel SMB server.\nAC:L - An attacker with access to a writable ACL-xattr share can deterministically store or arrange a malformed parent DACL and then create a child object to trigger inheritance; no race or uncontrollable condition is required.\nPR:L - The SMB2 CREATE path requires a valid SMB session and tree connection, and the practical attack requires share write/ACL-setting privileges, but not kernel, root, or administrative privileges.\nUI:N - After the attacker has SMB access, exploitation is driven entirely by attacker-sent SMB requests and does not require victim interaction.\nS:U - The vulnerable component and impacted resource are both within the same kernel/ksmbd security authority; this is not a VM escape or cross-boundary isolation bypass.\nC:H - The hardened ACE walk addresses attacker-controlled malformed DACL data that can drive out-of-bounds reads of kernel heap-backed security descriptor data; under the required high-severity tie-break rule, this is scored as high confidentiality impact.\nI:H - The malformed inherited ACE construction can corrupt kernel-managed ACL/security descriptor state and has plausible heap memory-corruption consequences, so the highest defensible integrity impact is high.\nA:H - The documented reproduction triggers a kernel allocator warning from attacker-controlled SMB activity, and such kernel warnings/oops conditions can crash or destabilize the server, especially with panic-on-warn configurations." } ] } ], "affected": [ { "product": "Linux", "vendor": "Linux", "defaultStatus": "unaffected", "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", "programFiles": [ "fs/smb/server/smbacl.c" ], "versions": [ { "version": "e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9", "lessThan": "063a7409b0de46d7c770b65bb0338e6fdb3b1f0a", "status": "affected", "versionType": "git" }, { "version": "e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9", "lessThan": "3e5360b422dd741cb315654a191fa73869a37414", "status": "affected", "versionType": "git" }, { "version": "e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9", "lessThan": "59c32abaaec9cdd6164811c7e864e72f7554b82d", "status": "affected", "versionType": "git" }, { "version": "e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9", "lessThan": "3e4e2ea2a781018ed5d75f969e3e5606beb66e48", "status": "affected", "versionType": "git" } ] }, { "product": "Linux", "vendor": "Linux", "defaultStatus": "affected", "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", "programFiles": [ "fs/smb/server/smbacl.c" ], "versions": [ { "version": "5.15", "status": "affected" }, { "version": "0", "lessThan": "5.15", "status": "unaffected", "versionType": "semver" }, { "version": "6.12.84", "lessThanOrEqual": "6.12.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.18.25", "lessThanOrEqual": "6.18.*", "status": "unaffected", "versionType": "semver" }, { "version": "7.0.2", "lessThanOrEqual": "7.0.*", "status": "unaffected", "versionType": "semver" }, { "version": "7.1", "lessThanOrEqual": "*", "status": "unaffected", "versionType": "original_commit_for_fix" } ] } ], "cpeApplicability": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.15", "versionEndExcluding": "6.12.84" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.15", "versionEndExcluding": "6.18.25" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.15", "versionEndExcluding": "7.0.2" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.15", "versionEndExcluding": "7.1" } ] } ] } ], "references": [ { "url": "https://git.kernel.org/stable/c/063a7409b0de46d7c770b65bb0338e6fdb3b1f0a" }, { "url": "https://git.kernel.org/stable/c/3e5360b422dd741cb315654a191fa73869a37414" }, { "url": "https://git.kernel.org/stable/c/59c32abaaec9cdd6164811c7e864e72f7554b82d" }, { "url": "https://git.kernel.org/stable/c/3e4e2ea2a781018ed5d75f969e3e5606beb66e48" } ], "title": "ksmbd: validate num_aces and harden ACE walk in smb_inherit_dacl()", "x_generator": { "engine": "bippy-1.2.0" } } } }