{
  "affected": [
    {
      "ranges": [
        {
          "events": [
            {
              "introduced": "282cbbb476b9f35793452bc461934af4c7eca169"
            },
            {
              "fixed": "5500ba1d410aed1eded3eb04a76b10cfb4409334"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        },
        {
          "events": [
            {
              "introduced": "f20adc4ef7428bc485ee83fd1a592252fb87718b"
            },
            {
              "fixed": "f6324b4240cf0b26a84c33f68a1222d727ff4af2"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        },
        {
          "events": [
            {
              "introduced": "325d4ac11f526cb8964cff14548ccf02d8c756d8"
            },
            {
              "fixed": "0fe08c5776a798f46df1fd74b331be26bdd644d6"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        },
        {
          "events": [
            {
              "introduced": "95e5aa3c3261da8c95b27d7aecf8ee39b9f86a4c"
            },
            {
              "fixed": "d333af32e4451285e427f2d9c29de3a39f6f6d48"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        },
        {
          "events": [
            {
              "introduced": "90089584b2e25c4510b7b987387b4405f0673ece"
            },
            {
              "fixed": "94215d55b09445993929f4fc966061d61de74929"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        },
        {
          "events": [
            {
              "introduced": "151b1799861fde38087c08f613abc2843ef597b0"
            },
            {
              "fixed": "4f7c131d2bdd7cd64b96f60d10be5ea72253f520"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        },
        {
          "events": [
            {
              "introduced": "d07b26f39246a82399661936dd0c853983cfade7"
            },
            {
              "fixed": "0e60dafe97eca61721f3db456f97d97a80c6c8ae"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        }
      ]
    },
    {
      "package": {
        "ecosystem": "Linux",
        "name": "Kernel"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "6.6.140"
            },
            {
              "fixed": "6.6.143"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.12.84"
            },
            {
              "fixed": "6.12.93"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.18.25"
            },
            {
              "fixed": "6.18.35"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "7.0.2"
            },
            {
              "fixed": "7.0.12"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "database_specific": {
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63909.json"
  },
  "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: OOB read regression in smb_check_perm_dacl() ACE-walk loops\n\nCommit d07b26f39246 (\"ksmbd: require minimum ACE size in\nsmb_check_perm_dacl()\") introduced a transposed bounds check:\n\n    if (offsetof(struct smb_ace, sid) + aces_size \u003c CIFS_SID_BASE_SIZE)\n\nSince offsetof(..sid) is 8 and CIFS_SID_BASE_SIZE is 8, this evaluates\nto `aces_size \u003c 0`. Because `aces_size` is always non-negative, this\ncheck becomes dead code and never breaks the loop.\n\nWorse, that commit removed the old 4-byte guard, meaning the loop now\nreads `ace-\u003esize` (offset 2) even when `aces_size` is 0-3 bytes. This\nre-opens a 2-byte heap out-of-bounds (OOB) read past the pntsd allocation\nduring subsequent SMB2_CREATE operations.\n\nFix this by properly transposing the comparison to require at least\n16 bytes (8-byte offset + 8-byte SID base), matching the correct form\nused in smb_inherit_dacl().",
  "id": "CVE-2026-63909",
  "modified": "2026-07-21T03:41:56.564258767Z",
  "published": "2026-07-19T14:55:15.060Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/0e60dafe97eca61721f3db456f97d97a80c6c8ae"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/0fe08c5776a798f46df1fd74b331be26bdd644d6"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/4f7c131d2bdd7cd64b96f60d10be5ea72253f520"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/5500ba1d410aed1eded3eb04a76b10cfb4409334"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/94215d55b09445993929f4fc966061d61de74929"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/d333af32e4451285e427f2d9c29de3a39f6f6d48"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/f6324b4240cf0b26a84c33f68a1222d727ff4af2"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63909.json"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-63909"
    },
    {
      "type": "PACKAGE",
      "url": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"
    }
  ],
  "schema_version": "1.8.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H",
      "type": "CVSS_V3"
    }
  ],
  "summary": "ksmbd: OOB read regression in smb_check_perm_dacl() ACE-walk loops"
}