SEPTEMBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-63909

HIGH · CVSS 8.1 EPSS 0.63%

Source: NVD + CISA KEV + EPSS · Published 2026-07-19 · Last synced 2026-08-18

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's ksmbd component, specifically in the smb_check_perm_dacl() function, where a regression allows for an out-of-bounds (OOB) read due to a flawed bounds check. This can lead to potential information disclosure during SMB2_CREATE operations, as the loop may read beyond allocated memory, exposing sensitive data. Organizations using Linux systems with SMB capabilities should prioritize patching this vulnerability to mitigate the risk of data leakage.

CVE
CVE-2026-63909
Severity
HIGH
CVSS
8.1
EPSS
0.63%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: ksmbd: OOB read regression in smb_check_perm_dacl() ACE-walk loops Commit d07b26f39246 ("ksmbd: require minimum ACE size in smb_check_perm_dacl()") introduced a transposed bounds check: if (offsetof(struct smb_ace, sid) + aces_size < CIFS_SID_BASE_SIZE) Since offsetof(..sid) is 8 and CIFS_SID_BASE_SIZE is 8, this evaluates to `aces_size < 0`. Because `aces_size` is always non-negative, this check becomes dead code and never breaks the loop. Worse, that commit removed the old 4-byte guard, meaning the loop now reads `ace->size` (offset 2) even when `aces_size` is 0-3 bytes. This re-opens a 2-byte heap out-of-bounds (OOB) read past the pntsd allocation during subsequent SMB2_CREATE operations. Fix this by properly transposing the comparison to require at least 16 bytes (8-byte offset + 8-byte SID base), matching the correct form used in smb_inherit_dacl().