Linux Kernel Vulnerability in SMB Server Affects Security Descriptor Validation
CVE-2026-64138
What is CVE-2026-64138?
A vulnerability in the Linux kernel's SMB server component, ksmbd, allows for unsafe validation of Security Identifiers (SIDs) in the parent security descriptors during Access Control List (ACL) inheritance. The introduced smb_validate_ntsd_sid() function enhances the validation process for Owner SID and Group SID within the NT Security Descriptor retrieved from parent directories, ensuring that only properly validated SIDs are referenced. This measure mitigates potential access control weaknesses introduced by flawed SID management, contributing to overall system integrity.
Affected Version(s)
Linux e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9
Linux e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 < 18d8db24b0a5b7be4829238dd4022236df02d421
Linux e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 < 1c9d0646a9959752f11ca1080dc1ff26bd1756cb