CVE-2026-68098
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
10/08/2026
Last modified:
17/08/2026
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
ksmbd: bound DACL dedup walk to copied ACEs<br />
<br />
set_ntacl_dacl() can stop copying ACEs before consuming the full input<br />
DACL when size accounting overflows.<br />
<br />
When that happens, num_aces reflects only the ACEs that were actually<br />
copied into the output DACL, but set_posix_acl_entries_dacl() still<br />
receives nt_num_aces and uses it to walk the existing ACE array during<br />
dedup.<br />
<br />
That makes the dedup walk scan past the copied ACE array and inspect<br />
buffer tail that does not contain valid ACEs.<br />
<br />
Split the two meanings currently carried by the NT ACE count. Pass the<br />
number of copied NT ACEs to bound the dedup walk, and preserve the<br />
original "input DACL had NT ACEs" state separately for the<br />
Everyone/default ACL fallback.<br />
<br />
This keeps the dedup walk aligned with the ACEs that are actually<br />
present in the rebuilt DACL.
Impact
Base Score 3.x
8.80
Severity 3.x
HIGH
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/58d97fcd0bf1aee694e244cc28635b9df95b543b
- https://git.kernel.org/stable/c/6d9d7aa4a2c99c31acfa28921c30b684110cf66c
- https://git.kernel.org/stable/c/a0ebdaa79e10210d4e8ed9fe138e8f4d569719e3
- https://git.kernel.org/stable/c/b057a851129c6a084e7e393b62ca3abf6c2660bc
- https://git.kernel.org/stable/c/f1eba60db813ec28732bf18b5f0a67ebac9c3100


