CVE-2026-46139 Details
Description
In the Linux kernel, the following vulnerability has been resolved: smb: client: use kzalloc to zero-initialize security descriptor buffer Commit 62e7dd0a39c2d ("smb: common: change the data type of num_aces to le16") split struct smb_acl's __le32 num_aces field into __le16 num_aces and __le16 reserved. The reserved field corresponds to Sbz2 in the MS-DTYP ACL wire format, which must be zero [1]. When building an ACL descriptor in build_sec_desc(), we are using a kmalloc()'ed descriptor buffer and writing the fields explicitly using le16() writes now. This never writes to the 2 byte reserved field, leaving it as uninitialized heap data. When the reserved field happens to contain non-zero slab garbage, Samba rejects the security descriptor with "ndr_pull_security_descriptor failed: Range Error", causing chmod to fail with EINVAL. Change kmalloc() to kzalloc() to ensure the entire buffer is zero-initialized. [1] https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-dtyp/20233ed8-a6c6-4097-aafa-dd545ed24428
A vulnerability exists in the Linux kernel's SMB client implementation, specifically in how security descriptor buffers are initialized. The issue arises from a change in the data type of the 'num_aces' field within the ACL structure, which introduced a reserved field that must be zero. When the ACL descriptor is built, the buffer is allocated using 'kmalloc', leaving the reserved field uninitialized. This uninitialized data can lead to errors when Samba processes the security descriptor, causing operations like 'chmod' to fail. The vulnerability is present in the Linux kernel stable tree.
The vulnerability has been addressed by changing the buffer allocation from 'kmalloc' to 'kzalloc', ensuring that the entire buffer is zero-initialized. Users should update to the latest version of the Linux kernel where this fix has been applied.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/4c3ed344a970aad51388ac3b0145b98318f0e21f | kernel.org | Patch |
| https://git.kernel.org/stable/c/5e489c6c47a2ac15edbaca153b9348e42c1eacab | kernel.org | Patch |
| https://git.kernel.org/stable/c/941a1e6eb35440336913afc88a82103291956d5d | kernel.org | Patch |
| https://git.kernel.org/stable/c/9bdb2ca31368b7671949dfb94a5d57ffccd01edd | kernel.org | Patch |
| https://git.kernel.org/stable/c/be1ef9512a3f5a755895c24f31b334342f4aa15b | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-908 | Use of Uninitialized Resource | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 6.12.23, < 6.12.88 >= 6.13.11, < 6.14 >= 6.14.1, < 6.18.30 >= 6.19, < 7.0.7 6.14 - 6.14 rc6 6.14 rc7 7.1 rc1 7.1 rc2 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 24, 2026 | Initial Analysis | [email protected] |
| Jun 17, 2026 | CVE Modified | kernel.org |
| May 28, 2026 | New CVE Received | kernel.org |