CVE-2026-90153
Received Received - Intake

BaseFortify

Vulnerability report for CVE-2026-90153, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-17

Last updated on: 2026-09-18

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: ksmbd: bound smb_check_perm_dacl() ACE walks by DACL size smb_check_perm_dacl() validates that the DACL fits inside the NT security descriptor, but then bounds its two ACE walks by the remaining NTSD length (acl_size) rather than the DACL's declared size (pdacl_size). When pdacl->size is smaller than the trailing NTSD buffer, bytes after the declared DACL boundary - still inside the stored security descriptor - are parsed as ACEs during access checks. A crafted DACL can place an access-granting ACE beyond pdacl->size, and the current code accepts it during SMB2_CREATE access validation, while parse_dacl() and smb_inherit_dacl() stop at pdacl_size. Bound both ACE walks by pdacl_size to match the DACL boundary semantics used elsewhere in the server. Validation: - semantic KUnit harness shows the post-boundary ACE is selected before the fix and rejected (EACCES) after it - linux master (7.2-rc6), x86_64

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-17
Last Modified
2026-09-18
Generated
2026-10-10
EPSS Evaluated
2026-10-09
NVD

Affected Vendors & Products

Showing 12 associated CPEs
Vendor Product Version / Range
Linux Linux 8f0541186e9ad1b62accc9519cc2b7a7240272a7
Linux Linux 8f0541186e9ad1b62accc9519cc2b7a7240272a7
Linux Linux 8f0541186e9ad1b62accc9519cc2b7a7240272a7
Linux Linux 8f0541186e9ad1b62accc9519cc2b7a7240272a7
Linux Linux 8f0541186e9ad1b62accc9519cc2b7a7240272a7
Linux Linux cb69d4d6f709f87c94afa28ae64c501576692171
Linux Linux 6e8f4abf584253cbaa596ea4ad13110cf61cd4c9
Linux Linux 8e33102309bd6839b2e2e158f93a7b378cb4655d
Linux Linux 5.15.62
Linux Linux 5.18.18
Linux Linux 5.19.2
Linux Linux 6.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
AI Quick Actions have not been generated yet.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-90153. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart