← All Advisories

CVE-2026-93811

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-93811

Key Details

CVECVE-2026-93811
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

ksmbd: Fix acl.sd_buf memory leak and invalid sd_size error handling

1. When ndr_decode_v4_ntacl() fails, the code jumped to free_n_data

which only freed n.data, skipping kfree(acl.sd_buf) and leaking

the buffer. Zero-initialize struct xattr_ntacl acl, reorder error

labels to out_free to release acl.sd_buf on all error paths.

2. if (acl.sd_size < sizeof(struct smb_ntsd)) is true, original code

returned success without freeing sd_buf and left stale *pntsd.

Set rc = -EINVAL before jumping to out_free to return error code and

free buffer. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-93811
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-93811