Overview
About vulnerability
In the Linux kernel, the following vulnerability has been resolved: smb: client: require a full NFS mode SID before reading mode bits parse_dacl() treats an ACE SID matching sid_unix_NFS_mode as an NFS mode SID and reads sid.sub_auth[2] to recover the mode bits. That assumes the ACE carries three subauthorities, but compare_sids() only compares min(a, b) subauthorities. A malicious server can return an ACE with num_subauth = 2 and sub_auth[] = {88, 3}, which still matches sid_unix_NFS_mode and then drives the sub_auth[2] read four bytes past the end of the ACE. Require num_subauth >= 3 before treating the ACE as an NFS mode SID. This keeps the fix local to the special-SID mode path without changing compare_sids() semantics for the rest of cifsacl. A flaw was found in the Linux kernel CIFS/SMB client when parsing DACLs (parse_dacl). An ACE could match the Unix NFS mode SID prefix with only two subauthorities; code then read sub_auth[2] for mode bits, accessing four bytes past the end of the ACE buffer. Upstream requires num_subauth >= 3 before treating an ACE as an NFS mode SID.
Details
KernelCare state
Live-patch status from KernelCare for each operating system.
| Operating system | Status | Covered kernels |
|---|---|---|
| Amazon Linux 2023 | Planned | — |
| Debian 11 | In Rollout |
37 kernels
|
| Debian 11 cloud | In Rollout |
17 kernels
|
| Debian 12 | Planned | — |
| Debian 13 | Planned | — |
| Ubuntu 24.04 | Planned | — |