PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-43350 Linux kernel CVE debrief

CVE-2026-43350 is a Linux kernel SMB/CIFS client memory-safety issue in the DACL parsing path. A malicious server can return an ACE whose SID is short enough to match the special NFS mode SID check, but still lacks the third subauthority that the code later reads. That can drive an out-of-bounds read past the end of the ACE when mode bits are recovered.

Vendor
Linux kernel
Product
Linux kernel
CVSS
HIGH 7.6
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-08
Original CVE updated
2026-06-19
Advisory published
2026-05-08
Advisory updated
2026-06-19

Who should care

Linux administrators and security teams running SMB/CIFS client workloads, especially systems that mount shares from untrusted or attacker-controlled SMB servers.

Technical summary

The issue is in parse_dacl() in the SMB client. The code treats an ACE SID matching sid_unix_NFS_mode as an NFS mode SID and then reads sid.sub_auth[2] to reconstruct permission bits. The problem is that compare_sids() only compares the minimum number of subauthorities between two SIDs, so an ACE with num_subauth = 2 can still match the special SID. If that happens, the subsequent sub_auth[2] access reads four bytes past the end of the ACE. The fix is to require num_subauth >= 3 before taking the NFS-mode path, while leaving compare_sids() behavior unchanged for other cifsacl uses.

Defensive priority

High

Recommended defensive actions

  • Backport and deploy the kernel fix that requires num_subauth >= 3 before the NFS mode SID path is taken.
  • Prioritize patching systems that connect to untrusted SMB/CIFS servers or accept remotely provided ACLs.
  • Review exposure for kernels with SMB/CIFS client support enabled and schedule updates according to your normal kernel emergency patch process.
  • Monitor vendor advisories and kernel stable updates for the commit series referenced in the CVE record.

Evidence notes

The supplied CVE description states that parse_dacl() can read sid.sub_auth[2] after a compare_sids() match even when the ACE has only two subauthorities, and that a malicious server can send num_subauth = 2 with sub_auth[] = {88, 3}. The CVSS vector in the record is CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H, which supports network reachability and user interaction requirements. Supplied timeline fields show CVE published at 2026-05-08T14:16:45.123Z and modified at 2026-05-11T08:16:10.797Z.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-43350 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-43350

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-43350 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-43350

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/2757ad3e4b6f9e0fed4c7739594e702abc5cab21

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/38a69f08ee82c450d3e4168707fff2e317dc3ff7

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/b53b8e98c23310294fc45fc686db5ee860311896

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/c8eef12af1cc73031639ea7cf16e0b10e2536b0b

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/f8488c07bea2431ee12a6067d736578064fa46b4

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.