« Volver al listado

CVE-2026-97564

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

smb: client: reject userspace cifs.idmap descriptions

cifs.idmap key descriptions carry authority-bearing fields (owner and group SIDs and uid/gid values in "os:"/"gs:"/"oi:"/"gi:" form) that the cifs.idmap upcall helper treats as kernel-originating inputs. Unlike its sibling cifs.spnego, the cifs.idmap key type has no vet_description hook, so userspace can create keys of this type through request_key(2)/add_key(2) and supply those fields without CIFS origin. A request_key(2) call with a non-NULL callout then drives a root usermodehelper upcall (/sbin/request-key -> cifs.idmap) that consumes the unvetted description in root context.

Leer descripción completaMostrar menos

Only accept cifs.idmap descriptions while CIFS is using its private root_cred to request the key. id_to_sid()/sid_to_id() already run under override_creds(root_cred), so the kernel-originated path is unaffected.

This mirrors commit 3da1fdf4efbc ("smb: client: reject userspace cifs.spnego descriptions"), which applied the same restriction to cifs.spnego.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-97564",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4d79dba0e00749fa40de8ef13a9b85ce57a1603b",
              "lessThan": "f29c1ec0e7d8c887a91df3f93bb4617c0ac95c6a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "4d79dba0e00749fa40de8ef13a9b85ce57a1603b",
              "lessThan": "17c93bcd17755523c21abb22cbf2a41a6eb0caaf",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "4d79dba0e00749fa40de8ef13a9b85ce57a1603b",
              "lessThan": "e5964064e3fbe6325893408faff08ca33de0e2c3",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "4d79dba0e00749fa40de8ef13a9b85ce57a1603b",
              "lessThan": "96751028c0d4dec785709ea3eb0ab38a4f2ded96",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "4d79dba0e00749fa40de8ef13a9b85ce57a1603b",
              "lessThan": "1d3b24b16a0b013792e8f1e3ed060f0b46f537d1",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "4d79dba0e00749fa40de8ef13a9b85ce57a1603b",
              "lessThan": "d9d7eeb0cea5b55b82888f443622fd8d4ee064f3",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "fs/smb/client/cifsacl.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "3.0"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "3.0",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.1.189",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.158",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.111",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.53",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.7",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc3",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "fs/smb/client/cifsacl.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-25T11:17:07.007",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/17c93bcd17755523c21abb22cbf2a41a6eb0caaf",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/1d3b24b16a0b013792e8f1e3ed060f0b46f537d1",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/96751028c0d4dec785709ea3eb0ab38a4f2ded96",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/d9d7eeb0cea5b55b82888f443622fd8d4ee064f3",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/e5964064e3fbe6325893408faff08ca33de0e2c3",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/f29c1ec0e7d8c887a91df3f93bb4617c0ac95c6a",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: reject userspace cifs.idmap descriptions\n\ncifs.idmap key descriptions carry authority-bearing fields (owner and\ngroup SIDs and uid/gid values in \"os:\"/\"gs:\"/\"oi:\"/\"gi:\" form) that the\ncifs.idmap upcall helper treats as kernel-originating inputs.  Unlike\nits sibling cifs.spnego, the cifs.idmap key type has no vet_description\nhook, so userspace can create keys of this type through\nrequest_key(2)/add_key(2) and supply those fields without CIFS origin.\nA request_key(2) call with a non-NULL callout then drives a root\nusermodehelper upcall (/sbin/request-key -> cifs.idmap) that consumes\nthe unvetted description in root context.\n\nOnly accept cifs.idmap descriptions while CIFS is using its private\nroot_cred to request the key.  id_to_sid()/sid_to_id() already run\nunder override_creds(root_cred), so the kernel-originated path is\nunaffected.\n\nThis mirrors commit 3da1fdf4efbc (\"smb: client: reject userspace\ncifs.spnego descriptions\"), which applied the same restriction to\ncifs.spnego."
    }
  ],
  "lastModified": "2026-10-03T11:18:03.980",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}