PT-2026-98501 · Linux · Linux Kernel
CVE-2026-97561
·
Published
2026-09-25
·
Updated
2026-09-28
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
An issue exists in the SMB client where the system fails to honor
forceuid and forcegid mount options when mapping Security Identifiers (SIDs) to user and group IDs. Certain code paths unconditionally call the sid to id() function, which overwrites cf uid and cf gid with values provided by the server, ignoring the administrator's explicit overrides. This occurs within the smb311 posix info to fattr(), cifs posix to fattr(), and parse sec desc() functions. Consequently, an untrusted server can dictate local file ownership even when the mount is configured to force specific uid or gid values.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel