CVE-2026-64380: smb: client: harden POSIX SID length parsing
In the Linux kernel, the following vulnerability has been resolved:
smb: client: harden POSIX SID length parsing
posixinfosidsize() reads sid[1] to obtain the subauthority count, but its existing boundary check still accepts buffers with only one remaining byte. Require two bytes before reading sid[1] so all client paths that reuse the helper reject truncated POSIX SIDs safely.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.6.145.2-1 - Compensating control
For the SMB client hardening (POSIX SID length parsing), ensure the POSIX SID helper requires at least two bytes before reading sid[1] to get the subauthority count, and reject buffers that contain only one remaining byte (truncated POSIX SIDs).
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
The CVSS vector indicates network reachability with low attack complexity, no privileges, and no user interaction required. Exploitation would involve causing the SMB client to process a truncated POSIX SID.
Which systems are exposed?
Systems using the Linux kernel SMB client are relevant, because the affected parsing helper is used by SMB client paths that handle POSIX SIDs. The listed software includes Linux kernel and Microsoft azl3 kernel 6.6.144.1-1.
What is the impact if the issue is exploited?
The supplied CVSS score is 8.2 high, with low confidentiality impact, no integrity impact, and high availability impact. This indicates the primary risk is a significant availability disruption.
How can I determine whether a fix is available?
Check the kernel source or vendor update information for one of the referenced stable commits: 0de5b8e76847f5de26f364a82c6602c4881c30da, 171605aed68380c2fa75dff9b3a1ed427c50065b, or 4213c1208978483021d7d125c131de3985d38f61. The fix changes the POSIX SID length validation to require at least two bytes before reading the subauthority count.