{"id":"CVE-2026-46195","title":"smb: client: validate dacloffset before building DACL pointers","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: validate dacloffset before building DACL pointers\n\nparse_sec_desc(), build_sec_desc(), and the chown path in\nid_mode_to_cifs_acl() all add the server-suppl…","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cvssSource":"cna","vendor":"Linux","product":"Linux","affected":["Linux >= bc3e9dd9d104ca1b75644eab87b38ce8a924aef4 < 5de2665e913a10ad70aaeecf736b97276e83d995","Linux >= bc3e9dd9d104ca1b75644eab87b38ce8a924aef4 < f9dc3be8f403c1216df73e57221f44b045e7ee0b","Linux >= bc3e9dd9d104ca1b75644eab87b38ce8a924aef4 < ba7f71b6161c0943dafc367565e5843d16b7d505","Linux >= bc3e9dd9d104ca1b75644eab87b38ce8a924aef4 < 3b1ddba19e77ee35241cd27f16dc3e8d14e08db7","Linux >= bc3e9dd9d104ca1b75644eab87b38ce8a924aef4 < c688f3ed73d31943334ad2139cb02ec49664322a","Linux >= bc3e9dd9d104ca1b75644eab87b38ce8a924aef4 < 8bd07e417b6bda67e317920584e48cb6ee442a8a","Linux >= bc3e9dd9d104ca1b75644eab87b38ce8a924aef4 < f98b48151cc502ada59d9778f0112d21f2586ca3","Linux 5.12"],"published":"2026-05-28","updated":"2026-09-11","sourceUpdated":"2026-09-11T12:09:11.879Z","source":"CVEORG","sourceUrl":"https://www.cve.org/CVERecord?id=CVE-2026-46195","references":[{"url":"https://git.kernel.org/stable/c/5de2665e913a10ad70aaeecf736b97276e83d995"},{"url":"https://git.kernel.org/stable/c/f9dc3be8f403c1216df73e57221f44b045e7ee0b"},{"url":"https://git.kernel.org/stable/c/ba7f71b6161c0943dafc367565e5843d16b7d505"},{"url":"https://git.kernel.org/stable/c/3b1ddba19e77ee35241cd27f16dc3e8d14e08db7"},{"url":"https://git.kernel.org/stable/c/c688f3ed73d31943334ad2139cb02ec49664322a"},{"url":"https://git.kernel.org/stable/c/8bd07e417b6bda67e317920584e48cb6ee442a8a"},{"url":"https://git.kernel.org/stable/c/f98b48151cc502ada59d9778f0112d21f2586ca3"}],"tags":["cve.org"],"epss":0.00675,"epssPercentile":0.5079,"ingestedAt":"2026-09-11T18:53:56.572Z","slug":"CVE-2026-46195","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: validate dacloffset before building DACL pointers\n\nparse_sec_desc(), build_sec_desc(), and the chown path in\nid_mode_to_cifs_acl() all add the server-supplied dacloffset to pntsd\nbefore proving a DACL header fits inside the returned security\ndescriptor.\n\nOn 32-bit builds a malicious server can return dacloffset near\nU32_MAX, wrap the derived DACL pointer below end_of_acl, and then slip\npast the later pointer-based bounds checks. build_sec_desc() and\nid_mode_to_cifs_acl() can then dereference DACL fields from the wrapped\npointer in the chmod/chown rewrite paths.\n\nValidate dacloffset numerically before building any DACL pointer and\nreuse the same helper at the three DACL entry points.\n\n## Affected\n\n- `Linux >= bc3e9dd9d104ca1b75644eab87b38ce8a924aef4 < 5de2665e913a10ad70aaeecf736b97276e83d995`\n- `Linux >= bc3e9dd9d104ca1b75644eab87b38ce8a924aef4 < f9dc3be8f403c1216df73e57221f44b045e7ee0b`\n- `Linux >= bc3e9dd9d104ca1b75644eab87b38ce8a924aef4 < ba7f71b6161c0943dafc367565e5843d16b7d505`\n- `Linux >= bc3e9dd9d104ca1b75644eab87b38ce8a924aef4 < 3b1ddba19e77ee35241cd27f16dc3e8d14e08db7`\n- `Linux >= bc3e9dd9d104ca1b75644eab87b38ce8a924aef4 < c688f3ed73d31943334ad2139cb02ec49664322a`\n- `Linux >= bc3e9dd9d104ca1b75644eab87b38ce8a924aef4 < 8bd07e417b6bda67e317920584e48cb6ee442a8a`\n- `Linux >= bc3e9dd9d104ca1b75644eab87b38ce8a924aef4 < f98b48151cc502ada59d9778f0112d21f2586ca3`\n- `Linux 5.12`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":54,"depthScoreParts":{"impact":53.9,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}