Review reviewHigh

CVE-2026-64380

Linux

In the Linux kernel, the following vulnerability has been resolved: smb: client: harden POSIX SID length parsing posix_info_sid_size() reads sid[1] to obtain the subauthority count, but its existing boundary check still accepts buffers with only one remaining byte. Require two bytes before reading sid[1] so all client paths that reuse the helper reject truncated POSIX SIDs safely.

CVSS
8.2
EPSS
-
- percentile
CISA KEV
Not listed
Published
2026.07.25
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability-
Technical severityCVSS 8.2

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: smb: client: harden POSIX SID length parsing posix_info_sid_size() reads sid[1] to obtain the subauthority count, but its existing boundary check still accepts buffers with only one remaining byte. Require two bytes before reading sid[1] so all client paths that reuse the helper reject truncated POSIX SIDs safely.

Affected product and versions

Product
Linux
Affected versions
>= 349e13ad30b45998bb9937cfe0b32be6f951976d < 171605aed68380c2fa75dff9b3a1ed427c50065b, >= 349e13ad30b45998bb9937cfe0b32be6f951976d < 4213c1208978483021d7d125c131de3985d38f61, >= 349e13ad30b45998bb9937cfe0b32be6f951976d < 96e889bc1e759c83f25093e8c2f3da31b4973f30, >= 349e13ad30b45998bb9937cfe0b32be6f951976d < 0de5b8e76847f5de26f364a82c6602c4881c30da, >= 349e13ad30b45998bb9937cfe0b32be6f951976d < 427eb7eb46425fec845a43e861f3d6e2899cae59, >= 349e13ad30b45998bb9937cfe0b32be6f951976d < 86c5d470f5d42e61123b2f4b4f0b91f4eee5b980, >= 349e13ad30b45998bb9937cfe0b32be6f951976d < 46a84715a015cb48e1b9c219dc88c03d8a541ea4, >= 349e13ad30b45998bb9937cfe0b32be6f951976d < 7ad2bcf2441430bb2e918fb3ef9a90d775a6e422, >= 5.7
Fixed versions
No verified fixed-version field is available yet

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
CWE
Not available