PT-2026-69498 · Linux · Linux Kernel

CVE-2026-68097

·

Published

2026-08-10

·

Updated

2026-08-13

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description In the ksmbd module, the set ntacl dacl() function fails to verify that the declared Access Control Entry (ACE) size contains all sub-authorities described by the sid.num subauth field. This allows an undersized ACE to be copied, which can lead to the POSIX ACL deduplication walk inspecting data beyond the copied ACE boundary. Additionally, the initial bound check is insufficient as it only ensures the ACE size field is accessible before reading sid.num subauth further into the input buffer.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-68097

Affected Products

Linux Kernel