{"id":"AZL-104691","summary":"CVE-2026-97559 affecting package kernel 6.6.157.1-1","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: fail DACL rewrite when the new DACL exceeds 64K\n\nreplace_sids_and_copy_aces() and set_chmod_dacl() accumulate the size of\nthe DACL they build in a u16. That accumulator can wrap.\n\nvalidate_dacl() caps num_aces at (dacl_size - sizeof(struct smb_acl)) /\n20, i.e. 3276 for a maximally sized DACL, while each rewritten ACE can\ngrow to sizeof(struct smb_ace) (76 bytes) once its SID is replaced with\none carrying SID_MAX_SUB_AUTHORITIES sub-authorities. The worst case is\ntherefore sizeof(struct smb_acl) + 3276 * 76 = 248984 bytes, far beyond\nwhat a u16 can hold. A wraparound is reached with 863 ACEs.\n\nAfter the wraparound, ndacl_ptr-\u003esize becomes meaningless and the offset\nwill point anywhere in the ACE array. As a result, we will see\ncorruption of the DACL, which then gets sent to the server. This is not\nan out-of-bounds write as the allocation now covers the worst-case\nexpansion, so writes will always go into the buffer.\n\nAdjust the code to use a u32 internally and return -EOVERFLOW in the\noverflow case. The operation must be refused, because a DACL can only\nhold 2^16-1 bytes on the wire and larger DACLs cannot be represented.\n\nset_chmod_dacl() carries the same pattern and is fixed the same way. It\nonly wraps once the source DACL comes within roughly 380 bytes of the\n64K ceiling, but the failure mode is identical.","modified":"2026-09-27T05:34:32Z","published":"2026-09-25T11:17:06Z","upstream":["CVE-2026-97559"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-97559"}],"affected":[{"package":{"name":"kernel","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.6.157.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-104691.json"}}],"schema_version":"1.9.0"}