Integer overflow in Linux kernel - CVE-2026-97559
Published: September 28, 2026
Vulnerability details
The vulnerability allows a local user to corrupt a discretionary access control list (DACL).
The vulnerability exists due to an integer overflow in the SMB client DACL rewrite functions when rewritten access control entries cause a DACL to exceed 64K. A local user can trigger a DACL rewrite that exceeds 64K to corrupt a DACL.
The affected allocation covers the worst-case expansion, so writes remain within the allocated buffer.