CVE Database
/

CVE-2026-31611

Back to search

CVE-2026-31611

Published: Apr 24, 2026

Modified: Jun 1, 2026

PUBLISHED

CVSS v3.1

8.6

HIGH

Description

In the Linux kernel, the following vulnerability has been resolved: ksmbd: require 3 sub-authorities before reading sub_auth[2] parse_dacl() compares each ACE SID against sid_unix_NFS_mode and on match reads sid.sub_auth[2] as the file mode. If sid_unix_NFS_mode is the prefix S-1-5-88-3 with num_subauth = 2 then compare_sids() compares only min(num_subauth, 2) sub-authorities so a client SID with num_subauth = 2 and sub_auth = {88, 3} will match. If num_subauth = 2 and the ACE is placed at the very end of the security descriptor, sub_auth[2] will be 4 bytes past end_of_acl. The out-of-band bytes will then be masked to the low 9 bits and applied as the file's POSIX mode, probably not something that is good to have happen. Fix this up by forcing the SID to actually carry a third sub-authority before reading it at all.

VendorProductVersions

Linux

Linux

affected
e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 - < cf2148b880fb7c0fcd727202dbc4fd5d6998b9c2
affected
e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 - < b5b5d5936a50497fb151c0b122899a6894721c2b
affected
e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 - < 08f9e6d899b5c834bbcc239eae1bed58d9b15d2c
affected
e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 - < d2454f4a002d08560a60f214f392e6491cf11560
affected
e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 - < 46bbcd3ebfb3549c8da1838fc4493e79bd3241e7

+2 more versions

Linux

Linux

affected
5.15
unaffected
0 - < 5.15
unaffected
6.1.175 - <= 6.1.*
unaffected
6.6.136 - <= 6.6.*
unaffected
6.12.83 - <= 6.12.*

+4 more versions

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H

Attack Vector

Network

Attack Complexity

Low

Privileges Required

None

User Interaction

None

Scope

Unchanged

Confidentiality

Low

Integrity

Low

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now