---
id: CVE-2026-46195
title: 'smb: client: validate dacloffset before building DACL pointers'
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  smb: client: validate dacloffset before building DACL pointers

  parse_sec_desc(), build_sec_desc(), and the chown path in
  id_mode_to_cifs_acl() all add the server-suppl…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cvssSource: cna
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= bc3e9dd9d104ca1b75644eab87b38ce8a924aef4 <
    5de2665e913a10ad70aaeecf736b97276e83d995
  - >-
    Linux >= bc3e9dd9d104ca1b75644eab87b38ce8a924aef4 <
    f9dc3be8f403c1216df73e57221f44b045e7ee0b
  - >-
    Linux >= bc3e9dd9d104ca1b75644eab87b38ce8a924aef4 <
    ba7f71b6161c0943dafc367565e5843d16b7d505
  - >-
    Linux >= bc3e9dd9d104ca1b75644eab87b38ce8a924aef4 <
    3b1ddba19e77ee35241cd27f16dc3e8d14e08db7
  - >-
    Linux >= bc3e9dd9d104ca1b75644eab87b38ce8a924aef4 <
    c688f3ed73d31943334ad2139cb02ec49664322a
  - >-
    Linux >= bc3e9dd9d104ca1b75644eab87b38ce8a924aef4 <
    8bd07e417b6bda67e317920584e48cb6ee442a8a
  - >-
    Linux >= bc3e9dd9d104ca1b75644eab87b38ce8a924aef4 <
    f98b48151cc502ada59d9778f0112d21f2586ca3
  - Linux 5.12
published: '2026-05-28'
updated: '2026-09-11'
sourceUpdated: '2026-09-11T12:09:11.879Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2026-46195'
references:
  - url: 'https://git.kernel.org/stable/c/5de2665e913a10ad70aaeecf736b97276e83d995'
  - url: 'https://git.kernel.org/stable/c/f9dc3be8f403c1216df73e57221f44b045e7ee0b'
  - url: 'https://git.kernel.org/stable/c/ba7f71b6161c0943dafc367565e5843d16b7d505'
  - url: 'https://git.kernel.org/stable/c/3b1ddba19e77ee35241cd27f16dc3e8d14e08db7'
  - url: 'https://git.kernel.org/stable/c/c688f3ed73d31943334ad2139cb02ec49664322a'
  - url: 'https://git.kernel.org/stable/c/8bd07e417b6bda67e317920584e48cb6ee442a8a'
  - url: 'https://git.kernel.org/stable/c/f98b48151cc502ada59d9778f0112d21f2586ca3'
tags:
  - cve.org
epss: 0.01015
epssPercentile: 0.61771
ingestedAt: '2026-09-11T18:53:56.572Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

smb: client: validate dacloffset before building DACL pointers

parse_sec_desc(), build_sec_desc(), and the chown path in
id_mode_to_cifs_acl() all add the server-supplied dacloffset to pntsd
before proving a DACL header fits inside the returned security
descriptor.

On 32-bit builds a malicious server can return dacloffset near
U32_MAX, wrap the derived DACL pointer below end_of_acl, and then slip
past the later pointer-based bounds checks. build_sec_desc() and
id_mode_to_cifs_acl() can then dereference DACL fields from the wrapped
pointer in the chmod/chown rewrite paths.

Validate dacloffset numerically before building any DACL pointer and
reuse the same helper at the three DACL entry points.

## Affected

- `Linux >= bc3e9dd9d104ca1b75644eab87b38ce8a924aef4 < 5de2665e913a10ad70aaeecf736b97276e83d995`
- `Linux >= bc3e9dd9d104ca1b75644eab87b38ce8a924aef4 < f9dc3be8f403c1216df73e57221f44b045e7ee0b`
- `Linux >= bc3e9dd9d104ca1b75644eab87b38ce8a924aef4 < ba7f71b6161c0943dafc367565e5843d16b7d505`
- `Linux >= bc3e9dd9d104ca1b75644eab87b38ce8a924aef4 < 3b1ddba19e77ee35241cd27f16dc3e8d14e08db7`
- `Linux >= bc3e9dd9d104ca1b75644eab87b38ce8a924aef4 < c688f3ed73d31943334ad2139cb02ec49664322a`
- `Linux >= bc3e9dd9d104ca1b75644eab87b38ce8a924aef4 < 8bd07e417b6bda67e317920584e48cb6ee442a8a`
- `Linux >= bc3e9dd9d104ca1b75644eab87b38ce8a924aef4 < f98b48151cc502ada59d9778f0112d21f2586ca3`
- `Linux 5.12`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
