CVE 8.8 HIGH

Linux ksmbd Remote Memory Corruption via ACL Inheritance_CVE-2026-8449

8.8 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Description

Linux ksmbd contains a remote memory corruption vulnerability in the ACL inheritance path that allows remote clients with directory creation permissions to trigger a heap out-of-bounds read and subsequent heap corruption by setting a crafted DACL with a malformed SID containing an inflated num_subauth field. Attackers can exploit this vulnerability by creating a directory, setting the malicious DACL via SMB2_SET_INFO, and creating child entries to cause kernel instability, denial of service, or potentially achieve privilege escalation to kernel code execution.

Basic Information

ID CVE-2026-8449
Source VulnCheck
Published May 12, 2026 at 21:34
Modified May 12, 2026 at 21:35

Affected Product

Vendor Linux
Product ksmbd
Affected Versions Linux ksmbd 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.