---
id: CVE-2026-97555
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  smb: client: fix heap overflow in DACL owner/group rewrite

  When id_mode_to_cifs_acl rewrites an existing DACL, it allocates a
  buffer sized according to the on-disk DAC…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  smb: client: fix heap overflow in DACL owner/group rewrite

  When id_mode_to_cifs_acl rewrites an existing DACL, it allocates a
  buffer sized according to the on-disk DAC…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= bc3e9dd9d104ca1b75644eab87b38ce8a924aef4 <
    fb736ab4fb8c4fdb8b2f9ccd3a62e03d11549ca1
  - >-
    Linux >= bc3e9dd9d104ca1b75644eab87b38ce8a924aef4 <
    7fa84c9ca690643f429ae2709584a47e74b572c9
  - >-
    Linux >= bc3e9dd9d104ca1b75644eab87b38ce8a924aef4 <
    2a9aee9ef5622d58d8aafaa3263b3ffe70e2d9dd
  - >-
    Linux >= bc3e9dd9d104ca1b75644eab87b38ce8a924aef4 <
    0ee150794c75bcd0be0e24ff3394f433cbae18cc
  - Linux 5.12
published: '2026-09-25'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T15:17:58.803'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-97555'
references:
  - url: 'https://git.kernel.org/stable/c/0ee150794c75bcd0be0e24ff3394f433cbae18cc'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/2a9aee9ef5622d58d8aafaa3263b3ffe70e2d9dd'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/7fa84c9ca690643f429ae2709584a47e74b572c9'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/fb736ab4fb8c4fdb8b2f9ccd3a62e03d11549ca1'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-25T11:06:38.916Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

smb: client: fix heap overflow in DACL owner/group rewrite

When id_mode_to_cifs_acl rewrites an existing DACL, it allocates a
buffer sized according to the on-disk DACL length reported by
dacl_ptr->size. However, replace_sids_and_copy_aces may rewrite each
ACE with a new owner/group SID obtained from the cifs.idmap upcall.
Those SIDs can have up to SID_MAX_SUB_AUTHORITIES (15) sub-authorities,
making each ACE up to 76 bytes (sizeof(struct smb_ace)).

If the original DACL contains short SIDs (e.g., 1 sub-authority) while
the replacement SIDs are long, the rewritten ACEs overflow the
allocation.

Fix this by always budgeting for worst-case SID expansion: allocate
sizeof(struct smb_acl) plus num_aces * sizeof(struct smb_ace), which
covers the smb_acl header and room for every ACE at maximum SID size.
This replaces the previous split logic that used dacl_ptr->size for
cifsacl mounts but num_aces * sizeof(struct smb_ace) for mode_from_sid
mounts: both paths can trigger the same rewrite and need the same
headroom.

KASAN reports this as:
  BUG: KASAN: slab-out-of-bounds in build_sec_desc+0x1e8a/0x2680 [cifs]
  Write of size 4 at addr ffff8881a5e25374 by task chown/5298
  ...
  The buggy address is located 0 bytes to the right of
   allocated 884-byte region [ffff8881a5e25000, ffff8881a5e25374)

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
