{
  "affected": [
    {
      "ranges": [
        {
          "events": [
            {
              "introduced": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2"
            },
            {
              "fixed": "c9a8b60ce140a68d172452f418137fc7ddbae7db"
            },
            {
              "fixed": "da6e25842431982d5a53cf00d925b98c690f4467"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        },
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "7.2.7"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        }
      ]
    },
    {
      "package": {
        "ecosystem": "Linux",
        "name": "Kernel"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "7.2.7"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "database_specific": {
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/97xxx/CVE-2026-97554.json"
  },
  "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: avoid using uninitialized SIDs in cifs_posix_to_fattr()\n\ncifs_posix_to_fattr() ignores the return value of posix_info_parse().\nWhen a malformed POSIX directory entry is encountered (e.g. invalid\nSID lengths from an untrusted server), posix_info_parse() returns -1\nwithout populating the 'parsed' struct.  The uninitialized stack\nmemory in parsed.owner and parsed.group is then passed to\nsid_to_id(), which processes the garbage bytes and passes them to\nrequest_key() to construct a SID string, potentially leaking kernel\nstack contents to the userspace idmap daemon.\n\nFix this by checking the return value and skipping the SID-to-id\nmapping when parsing fails.  The remaining fattr fields (timestamps,\nmode, etc.) are populated directly from the 'info' pointer so they\nare unaffected.",
  "id": "CVE-2026-97554",
  "modified": "2026-09-27T03:30:19.216408002Z",
  "published": "2026-09-25T10:21:45.851Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/c9a8b60ce140a68d172452f418137fc7ddbae7db"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/da6e25842431982d5a53cf00d925b98c690f4467"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/97xxx/CVE-2026-97554.json"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-97554"
    },
    {
      "type": "PACKAGE",
      "url": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"
    }
  ],
  "schema_version": "1.9.0",
  "summary": "smb: client: avoid using uninitialized SIDs in cifs_posix_to_fattr()"
}