← All Advisories

CVE-2026-97559

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-97559

Key Details

CVECVE-2026-97559
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

smb: client: fail DACL rewrite when the new DACL exceeds 64K

replace_sids_and_copy_aces() and set_chmod_dacl() accumulate the size of

the DACL they build in a u16. That accumulator can wrap.

validate_dacl() caps num_aces at (dacl_size - sizeof(struct smb_acl)) /

20, i.e. 3276 for a maximally sized DACL, while each rewritten ACE can

grow to sizeof(struct smb_ace) (76 bytes) once its SID is replaced with

one carrying SID_MAX_SUB_AUTHORITIES sub-authorities. The worst case is

therefore sizeof(struct smb_acl) + 3276 * 76 = 248984 bytes, far beyond

what a u16 can hold. A wraparound is reached with 863 ACEs.

After the wraparound, ndacl_ptr->size becomes meaningless and the offset

will point anywhere in the ACE array. As a result, we will see

corruption of the DACL, which then gets sent to the server. This is not

an out-of-bounds write as the allocation now covers the worst-case

expansion, so writes will always go into the buffer.

Adjust the code to use a u32 internally and return -EOVERFLOW in the

overflow case. The operation must be refused, because a DACL can only

hold 2^16-1 bytes on the wire and larger DACLs cannot be represented.

set_chmod_dacl() carries the same pattern and is fixed the same way. It

only wraps once the source DACL comes within roughly 380 bytes of the

64K ceiling, but the failure mode is identical. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-97559
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-97559