CVE-2026-31709

Aliases:UBUNTU-CVE-2026-31709DEBIAN-CVE-2026-31709CGA-568w-3442-wq32CGA-59f7-cphr-xwcpCGA-74hw-6m82-g23vCGA-c54j-5q24-3352CGA-gcwm-mvj5-wq8fCGA-h798-3w27-c7q3CGA-h9ch-jgc3-p7pvCGA-j2pc-f555-frm7CGA-j934-3g84-fr2vCGA-jf9h-mr54-2xg2CGA-jp8h-2p47-hjxgCGA-jrfg-8654-j363CGA-mhg5-9mgw-xhv6CGA-q9vj-65gc-m855CGA-qw46-c49m-wrmrCGA-r67j-w32g-3hxvCGA-wff3-2x89-fvc2CGA-gc7h-h3xg-8v54CGA-m8gv-xjj7-mqj9CGA-23fw-cr99-cgxvCGA-4r34-gwfx-wvc2CGA-72p8-fr39-wr4hCGA-8jv6-47wv-97jcCGA-j9hw-mrqg-93jcCGA-jvf9-8q3j-26r2CGA-m6rv-433x-xj24CGA-m96g-f9wf-pp89CGA-mj7h-4fmf-w2pvCGA-mr6j-8w44-6x9xCGA-wjrq-g589-v67hCGA-xrxf-wh2p-vfh9
Modified
Published: 01 May 2026, 13:56
Last modified:05 Aug 2026, 12:24

Vulnerability Summary

Overall Risk (default)
medium
35/100
CVSS Score
8.8 HIGH
v3.1 (cve.org)
EPSS Score
0.26% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

01 May 2026, 13:56
Published
Vulnerability first disclosed
05 Aug 2026, 12:24
Last Modified
Vulnerability information updated

Description

In the Linux kernel, the following vulnerability has been resolved: smb: client: validate the whole DACL before rewriting it in cifsacl build_sec_desc() and id_mode_to_cifs_acl() derive a DACL pointer from a server-supplied dacloffset and then use the incoming ACL to rebuild the chmod/chown security descriptor. The original fix only checked that the struct smb_acl header fits before reading dacl_ptr->size or dacl_ptr->num_aces. That avoids the immediate header-field OOB read, but the rewrite helpers still walk ACEs based on pdacl->num_aces with no structural validation of the incoming DACL body. A malicious server can return a truncated DACL that still contains a header, claims one or more ACEs, and then drive replace_sids_and_copy_aces() or set_chmod_dacl() past the validated extent while they compare or copy attacker-controlled ACEs. Factor the DACL structural checks into validate_dacl(), extend them to validate each ACE against the DACL bounds, and use the shared validator before the chmod/chown rebuild paths. parse_dacl() reuses the same validator so the read-side parser and write-side rewrite paths agree on what constitutes a well-formed incoming DACL.

CVSS Metrics

  • v4.0HIGHScore: 7.1CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
  • v3.1HIGHScore: 8.8CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS Trends

Current EPSS score: 0.26% Percentile: 18%

Techniques & Countermeasures

  • CWE-1288Improper Validation of Consistency within Input

    The product receives a complex input with multiple elements or fields that must be consistent with each other, but it does not validate or incorrectly validates that the input is actually consistent.

Affected Systems

  • chainguardlinux-aws-6.12

    < 6.12.85-r2

  • chainguardlinux-aws-6.18

    < 6.18.35-r0

  • chainguardlinux-azure-6.12

    < 6.12.85-r2

  • chainguardlinux-azure-6.18

    < 6.18.35-r0 | < 6.18.24-r1

  • chainguardlinux-desktop-6.18

    all

  • chainguardlinux-desktop-6.18-bootc

    all

  • chainguardlinux-desktop-6.18-bootc-boot-installed

    all

  • chainguardlinux-desktop-6.18-headers

    all

  • chainguardlinux-desktop-6.18-modules

    all

  • chainguardlinux-firecracker-6.18

    all

  • chainguardlinux-gcp-6.12

    all

  • chainguardlinux-gcp-6.18

    < 6.18.35-r0

  • chainguardlinux-gcp-6.18-bootc

    < 6.18.35-r0

  • chainguardlinux-gcp-6.18-bootc-boot-installed

    < 6.18.38-r2

  • chainguardlinux-qemu-6.12

    < 6.12.89-r0 | all

  • chainguardlinux-qemu-6.18

    < 6.18.24-r3

  • chainguardlinux-qemu-melange

    < 6.18.34-r0 | all | < 6.18.49-r2

  • chainguardlinux-qemu-rc

    < 7.1_rc3-r0

  • chainguardlinux-vmware-6.12

    < 6.12.85-r2

  • chainguardlinux-vmware-6.18

    < 6.18.35-r0

  • debianlinux

    < 6.1.176-1 | < 6.12.86-1 | < 7.0.3-1

  • debianlinux-6.1

    < 6.1.176-1~deb11u1

  • ubuntulinux

    all | < 6.8.0-136.136 | all | < 7.0.0-27.27

  • ubuntulinux-allwinner-5.19

    all

  • ubuntulinux-aws

    all | < 6.8.0-1061.64 | all | < 7.0.0-1008.8

  • ubuntulinux-aws-5.0

    all

  • ubuntulinux-aws-5.11

    all

  • ubuntulinux-aws-5.13

    all

  • ubuntulinux-aws-5.15

    all

  • ubuntulinux-aws-5.19

    all

  • ubuntulinux-aws-5.3

    all

  • ubuntulinux-aws-5.8

    all

  • ubuntulinux-aws-6.14

    all

  • ubuntulinux-aws-6.17

    all

  • ubuntulinux-aws-6.2

    all

  • ubuntulinux-aws-6.5

    all

  • ubuntulinux-aws-6.8

    < 6.8.0-1061.64~22.04.1

  • ubuntulinux-aws-fips

    all | < 6.8.0-1061.64+fips1

  • ubuntulinux-azure

    all | all | < 6.8.0-1063.71 | all | < 7.0.0-1010.10

  • ubuntulinux-azure-5.11

    all

  • ubuntulinux-azure-5.13

    all

  • ubuntulinux-azure-5.15

    all

  • ubuntulinux-azure-5.19

    all

  • ubuntulinux-azure-5.3

    all

  • ubuntulinux-azure-5.8

    all

  • ubuntulinux-azure-6.11

    all

  • ubuntulinux-azure-6.14

    all

  • ubuntulinux-azure-6.17

    all

  • ubuntulinux-azure-6.2

    all

  • ubuntulinux-azure-6.5

    all

Showing first 50 affected entries in server-rendered view.

References (45)