---
id: CVE-2026-68099
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  ksmbd: restore DACL size on check_add_overflow() to avoid malformed ACL

  check_add_overflow() unconditionally writes the truncated sum into *d
  even on overflow, per its…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  ksmbd: restore DACL size on check_add_overflow() to avoid malformed ACL

  check_add_overflow() unconditionally writes the truncated sum into *d
  even on overflow, per its…
severity: none
published: '2026-08-10'
updated: '2026-08-23'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-68099'
references:
  - url: 'https://git.kernel.org/stable/c/0bf38372821b1526f31538a7d9811844c55c7f38'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/847ecd4eb3c117c3d2f13f1e7ab506543aad8183'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/8f3a7a499a7d9bb1c0f33fe78c4a4594d7e307f4'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/bbf0a8e931204ecdab494a88d43b0a24a04285c5'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/bc90144ce8bb7fcf05ad9417c7adb4e9509d9e13'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/f4fcd0c1a243d449307b887fafee23921e9db5ab'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
epss: 0.00173
epssPercentile: 0.06996
ingestedAt: '2026-08-23T13:48:05.827Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

ksmbd: restore DACL size on check_add_overflow() to avoid malformed ACL

check_add_overflow() unconditionally writes the truncated sum into *d
even on overflow, per its contract in include/linux/overflow.h.
The four check_add_overflow() guards in set_posix_acl_entries_dacl()
and set_ntacl_dacl() break out of the ACE-building loops on overflow,
but the truncated *size is then consumed downstream at the end of
set_ntacl_dacl():

    pndacl->size = cpu_to_le16(le16_to_cpu(pndacl->size) + size);

This produces an on-wire NT ACL whose pndacl->size under-reports the
bytes actually written by the preceding fill_ace_for_sid()/memcpy()
calls, yielding a malformed ACL that can trigger out-of-bounds reads
when re-parsed by clients or ksmbd itself.

Restore *size to its pre-addition value on each overflow branch (via
`*size -= ace_sz` / `size -= nt_ace_size`) so that after the break,
*size once again holds the cumulative size of the successfully-written
ACEs. The committed ACL is then truncated-but-self-consistent rather
than malformed.

The ksmbd DACL builders are the only check_add_overflow() sites found
where an overflow path breaks out of a loop and the destination value
is consumed afterward. The other nearby break-style cases either
return -EINVAL on overflow (transport_ipc.c) or break without
consuming the overflowed destination value afterward (buildid.c).

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
