CVE-2026-31706: ksmbd: validate num_aces and harden ACE walk in smb_inherit_dacl()
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: validate num_aces and harden ACE walk in smb_inherit_dacl()
smb_inherit_dacl() trusts the on-disk num_aces value from the parent
directory's DACL xattr and uses it to size a heap allocation:
aces_base = kmalloc(sizeof(struct smb_ace) * num_aces * 2, ...);
num_aces is a u16 read from le16_to_cpu(parent_pdacl->num_aces)
without checking that it is consistent with the declared pdacl_size.
An authenticated client whose parent directory's security.NTACL is
tampered (e.g. via offline xattr corruption or a concurrent path that
bypasses parse_dacl()) can present num_aces = 65535 with minimal
actual ACE data. This causes a ~8 MB allocation (not kzalloc, so
uninitialized) that the subsequent loop only partially populates, and
may also overflow the three-way size_t multiply on 32-bit kernels.
Additionally, the ACE walk loop uses the weaker
offsetof(struct smb_ace, access_req) minimum size check rather than
the minimum valid on-wire ACE size, and does not reject ACEs whose
declared size is below the minimum.
Reproduced on UML + KASAN + LOCKDEP against the real ksmbd code path.
A legitimate mount.cifs client creates a parent directory over SMB
(ksmbd writes a valid security.NTACL xattr), then the NTACL blob on
the backing filesystem is rewritten to set num_aces = 0xFFFF while
keeping the posix_acl_hash bytes intact so ksmbd_vfs_get_sd_xattr()'s
hash check still passes. A subsequent SMB2 CREATE of a child under
that parent drives smb2_open() into smb_inherit_dacl() (share has
"vfs objects = acl_xattr" set), which fails the page allocator:
WARNING: mm/page_alloc.c:5226 at __alloc_frozen_pages_noprof+0x46c/0x9c0
Workqueue: ksmbd-io handle_ksmbd_work
__alloc_frozen_pages_noprof+0x46c/0x9c0
___kmalloc_large_node+0x68/0x130
__kmalloc_large_node_noprof+0x24/0x70
__kmalloc_noprof+0x4c9/0x690
smb_inherit_dacl+0x394/0x2430
smb2_open+0x595d/0xabe0
handle_ksmbd_work+0x3d3/0x1140
With the patch applied the added guard rejects the tampered value
with -EINVAL before any large allocation runs, smb2_open() falls back
to smb2_create_sd_buffer(), and the child is created with a default
SD. No warning, no splat.
Fix by:
1. Validating num_aces against pdacl_size using the same formula
applied in parse_dacl().
2. Replacing the raw kmalloc(sizeof * num_aces * 2) with
kmalloc_array(num_aces * 2, sizeof(...)) for overflow-safe
allocation.
3. Tightening the per-ACE loop guard to require the minimum valid
ACE size (offsetof(smb_ace, sid) + CIFS_SID_BASE_SIZE) and
rejecting under-sized ACEs, matching the hardening in
smb_check_perm_dacl() and parse_dacl().
v1 -> v2:
- Replace the synthetic test-module splat in the changelog with a
real-path UML + KASAN reproduction driven through mount.cifs and
SMB2 CREATE; Namjae flagged the kcifs3_test_inherit_dacl_old name
in v1 since it does not exist in ksmbd.
- Drop the commit-hash citation from the code comment per Namjae's
review; keep the parse_dacl() pointer.
Security readout for executives and security teams
Plain-English summary
A flaw in Linux’s ksmbd SMB server can trust corrupted access-control metadata and make an excessive memory allocation when creating a child item. An authenticated SMB user may trigger the vulnerable path, but the parent directory’s security.NTACL data must first be tampered with through offline corruption or another path bypassing validation.
Executive priority
Prioritize expedited remediation for systems exposing ksmbd to authenticated users, especially where backing-filesystem metadata can be modified outside normal validation. The documented result is service disruption, while the CVSS score is 8.8. Systems not running ksmbd or lacking the prerequisite ACL path have materially lower urgency.
Technical view
smb_inherit_dacl() fails to validate num_aces against the DACL xattr size before allocation and inadequately validates individual ACE sizes. A crafted value can cause an approximately 8 MB allocation, partially initialized memory, or multiplication overflow on 32-bit kernels. The cited fixes add bounds validation, overflow-safe allocation, and stricter ACE parsing.
Likely exposure
Exposure is limited to affected Linux kernels running ksmbd where the relevant ACL xattr behavior is used. The demonstrated path requires an authenticated client, a share configured with acl_xattr behavior, and previously tampered parent security.NTACL metadata. The supplied version list is ambiguous, so deployed kernels require vendor-specific confirmation.
Exploitation context
The source describes successful reproduction through the real ksmbd path using UML, KASAN, mount.cifs, and SMB2 CREATE. It demonstrates an allocator warning and denial-of-service potential. KEV is false, and the bundle provides no evidence of active exploitation. Confidentiality, integrity, or code-execution impact was not demonstrated.
Researcher notes
The essential prerequisite is inconsistent on-disk DACL metadata: num_aces can greatly exceed the ACE data declared by pdacl_size. The patch validates that relationship, uses kmalloc_array(), and enforces a minimum on-wire ACE size. The evidence establishes allocator failure; broader confidentiality and integrity effects implied by CVSS remain unproven in the supplied material.
Mitigation direction
Update to a vendor-supported kernel containing the applicable cited stable fix.
Confirm kernel remediation status with the operating-system vendor because the supplied affected-version data is ambiguous.
Restrict authenticated SMB access to trusted users while patching is pending.
Investigate and correct unauthorized or corrupted security.NTACL extended attributes on SMB backing storage.
Validation and detection
Inventory systems running ksmbd and identify their exact kernel builds.
Determine whether SMB shares use the relevant acl_xattr configuration and inherited DACL path.
Verify the kernel includes the applicable stable fix or vendor backport.
Review kernel logs for allocation warnings referencing smb_inherit_dacl or ksmbd workqueues.
Assess whether any process can modify security.NTACL metadata without normal DACL validation.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cve · low confidence lookup
CVE-2026-31706 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
1CVSS vectors
3Timeline events
0ADP providers
5Source links
CVSS vector scores
1 official score
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.