In the Linux kernel, the following vulnerability has been resolved: ksmbd: bound DACL dedup walk to copied ACEs set_ntacl_dacl() can stop copying ACEs before consuming the full input DACL when size…
High CVSS 8.8
Summary
In the Linux kernel, the following vulnerability has been resolved: ksmbd: bound DACL dedup walk to copied ACEs set_ntacl_dacl() can stop copying ACEs before consuming the full input DACL when size accounting overflows. When that happens, num_aces reflects only the ACEs that were actually copied into the output DACL, but set_posix_acl_entries_dacl() still receives nt_num_aces and uses it to walk the existing ACE array during dedup. That makes the dedup walk scan past the copied ACE array an…
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Sources
- NVD DATABASE
Original Links
- https://git.kernel.org/stable/c/58d97fcd0bf1aee694e244cc28635b9df95b543b
- https://git.kernel.org/stable/c/6d9d7aa4a2c99c31acfa28921c30b684110cf66c
- https://git.kernel.org/stable/c/a0ebdaa79e10210d4e8ed9fe138e8f4d569719e3
- https://git.kernel.org/stable/c/b057a851129c6a084e7e393b62ca3abf6c2660bc
- https://git.kernel.org/stable/c/f1eba60db813ec28732bf18b5f0a67ebac9c3100
Timeline
- nvd_ingest NVD