{"schema_version":"1.9.0","id":"CVE-2026-63909","published":"2026-07-19T14:55:15.060Z","modified":"2026-08-12T03:51:22.256853102Z","summary":"ksmbd: OOB read regression in smb_check_perm_dacl() ACE-walk loops","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: OOB read regression in smb_check_perm_dacl() ACE-walk loops\n\nCommit d07b26f39246 (\"ksmbd: require minimum ACE size in\nsmb_check_perm_dacl()\") introduced a transposed bounds check:\n\n    if (offsetof(struct smb_ace, sid) + aces_size < CIFS_SID_BASE_SIZE)\n\nSince offsetof(..sid) is 8 and CIFS_SID_BASE_SIZE is 8, this evaluates\nto `aces_size < 0`. Because `aces_size` is always non-negative, this\ncheck becomes dead code and never breaks the loop.\n\nWorse, that commit removed the old 4-byte guard, meaning the loop now\nreads `ace->size` (offset 2) even when `aces_size` is 0-3 bytes. This\nre-opens a 2-byte heap out-of-bounds (OOB) read past the pntsd allocation\nduring subsequent SMB2_CREATE operations.\n\nFix this by properly transposing the comparison to require at least\n16 bytes (8-byte offset + 8-byte SID base), matching the correct form\nused in smb_inherit_dacl().","affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"282cbbb476b9f35793452bc461934af4c7eca169"},{"fixed":"5500ba1d410aed1eded3eb04a76b10cfb4409334"}]},{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"f20adc4ef7428bc485ee83fd1a592252fb87718b"},{"fixed":"f6324b4240cf0b26a84c33f68a1222d727ff4af2"}]},{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"325d4ac11f526cb8964cff14548ccf02d8c756d8"},{"fixed":"0fe08c5776a798f46df1fd74b331be26bdd644d6"}]},{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"95e5aa3c3261da8c95b27d7aecf8ee39b9f86a4c"},{"fixed":"d333af32e4451285e427f2d9c29de3a39f6f6d48"}]},{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"90089584b2e25c4510b7b987387b4405f0673ece"},{"fixed":"94215d55b09445993929f4fc966061d61de74929"}]},{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"151b1799861fde38087c08f613abc2843ef597b0"},{"fixed":"4f7c131d2bdd7cd64b96f60d10be5ea72253f520"}]},{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"d07b26f39246a82399661936dd0c853983cfade7"},{"fixed":"0e60dafe97eca61721f3db456f97d97a80c6c8ae"}]}],"versions":["v6.6.142","v6.6.141","v6.6.140","v6.12.92","v6.12.91","v6.12.90","v6.12.89","v6.12.88","v6.12.87","v6.12.86","v6.12.85","v6.12.84","v6.18.34","v6.18.33","v6.18.32","v6.18.31","v6.18.30","v6.18.29","v6.18.28","v6.18.27","v6.18.26","v6.18.25","v7.0.11","v7.0.10","v7.0.9","v7.0.8","v7.0.7","v7.0.6","v7.0.5","v7.0.4","v7.0.3","v7.0.2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63909.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"6.6.140"},{"fixed":"6.6.143"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.12.84"},{"fixed":"6.12.93"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.18.25"},{"fixed":"6.18.35"}]},{"type":"ECOSYSTEM","events":[{"introduced":"7.0.2"},{"fixed":"7.0.12"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63909.json"}}],"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/0e60dafe97eca61721f3db456f97d97a80c6c8ae"},{"type":"WEB","url":"https://git.kernel.org/stable/c/0fe08c5776a798f46df1fd74b331be26bdd644d6"},{"type":"WEB","url":"https://git.kernel.org/stable/c/4f7c131d2bdd7cd64b96f60d10be5ea72253f520"},{"type":"WEB","url":"https://git.kernel.org/stable/c/5500ba1d410aed1eded3eb04a76b10cfb4409334"},{"type":"WEB","url":"https://git.kernel.org/stable/c/94215d55b09445993929f4fc966061d61de74929"},{"type":"WEB","url":"https://git.kernel.org/stable/c/d333af32e4451285e427f2d9c29de3a39f6f6d48"},{"type":"WEB","url":"https://git.kernel.org/stable/c/f6324b4240cf0b26a84c33f68a1222d727ff4af2"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63909.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-63909"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63909.json"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H"}]}