CVE-2026-43490General(linux / linux_kernel)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch linux linux_kernel systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate inherited ACE SID length smb_inherit_dacl() walks the parent directory DACL loaded from the security descriptor xattr. It verifies that each ACE contains the fixed SID header before using it, but does not verify that the variable-length SID described by sid.num_subauth is fully contained in the ACE. A malformed inheritable ACE can advertise more subauthorities than are present in the ACE. compare_sids() may then read past the ACE. smb_set_ace() also clamps the copied destination SID, but used the unchecked source SID count to compute the inherited ACE size. That could advance the temporary inherited ACE buffer pointer and nt_size accounting past the allocated buffer. Fix this by validating the parent ACE SID count and SID length before using the SID during inheritance. Compute the inherited ACE size from the copied SID so the size matches the bounded destination SID. Reject the inherited DACL if size accumulation would overflow smb_acl.size or the security descriptor allocation size.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-787

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linux_kernel

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • General: 3 classified signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 2 mentions (2026-05-15); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
linux_kernel

1 version affected across 1 product

Deep dive

Activity timeline5 mentions / 3d
01122Mentions · 2026-05-15: 2Mentions · 2026-05-16: 2Mentions · 2026-05-18: 1Patch / Workaround · 2026-05-15: 1Technical Details · 2026-05-15: 105-1505-1605-18
Signal classification2 categories
General
360.0%
Disclosure
240.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-05-152
Disclosure2
2026-05-162
General2
2026-05-181
General1
Full discourse5 posts
  • yousukezan@yousukezan
    Disclosure

    Linux kernel のSMBサーバ実装「ksmbd」に、細工したACL継承処理によりリモートからカーネルメモリ破壊を引き起こす脆弱性「CVE-2026-43490」が公開された。 問題はSMB ACL継承処理「smb_inherit_dacl()」内のSID長検証不備にあり、攻撃者が細工済みDACLをSMB2_SET_INFO経由で設定後、子ディレクトリ作成を行うとヒープ領域外読み取りやslab-use-after-freeが発生する。研究者のKASAN再現環境では、num_subauth=255を宣言しながら実際には2件しか含まない不正SIDにより、カーネルメモリ破壊が確認された。 影響を受けるのはLinux ksmbdで、攻撃にはSMB共有へアクセスし、DACL設定と子エントリ作成権限を持つセッションが必要となる。実害としてカーネル不安定化やDoSが確認されており、権限昇格可能性も否定されていない。 修正はLinusツリーへ「996454bc0da8」として取り込まれ、6.12.88、6.18.30、7.0.7、7.1-rc3以降で修正済み。SID長検証追加と、継承ACEサイズ計算の修正が行われた。 https://zaizen.me/blog/ksmbd-smbacl-inherit-dacl-oob.html

    Post summary

    The post discloses a new CVE‑2026‑43490 in Linux ksmbd, detailing the ACL inheritance flaw and its exploitation path, confirms the impact, and documents the patch and affected kernel versions.

    035372228.8K
    14.5K followersView on X
  • Manabu Ori@orimanabu
    General

    Linuxカーネルのksmbdに関連する脆弱性 CVE-2026-43490 に関するRed Hat製品の情報はこちらにまとまっています https://access.redhat.com/security/cve/cve-2026-43490

    Post summary

    The post merely directs readers to a Red Hat page for CVE‑2026‑43490, without providing PoC, exploit, patch details, or evidence of active exploitation.

    10032532
    1.3K followersView on X
  • VulDB 🛡@vuldb
    General

    A severe vulnerability was disclosed for Linux Kernel (CVE-2026-43490) https://vuldb.com/vuln/364143

    Post summary

    The brief statement merely announces the disclosure of CVE‑2026‑43490 for the Linux kernel, without providing any additional technical or operational details.

    01010164
    2.2K followersView on X
  • VulDB 🛡@vuldb
    General

    Attention, elevated activities detected targeting Linux Kernel (CVE-2026-43490) https://vuldb.com/vuln/364143/cti

    Post summary

    The note alerts to increased activity around CVE‑2026‑43490 but lacks evidence of exploitation, PoC, or patch guidance, making it a general observation.

    00000111
    2.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-43490 Linux Kernel ksmbd Inherited ACE SID Length Validation Vulnerability https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-43490

    Post summary

    The text announces the existence of CVE-2026-43490 with a brief description, but provides no PoC, exploit, active use, patch information, or technical details.

    00000100
    4.0K followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
OSlinuxlinux_kernel---
OSlinuxlinux_kernel7.1--
OSlinuxlinux_kernel7.1--

Explore more