CVE-2026-97564

Source
https://cve.org/CVERecord?id=CVE-2026-97564
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-97564.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-97564
Downstream
Published
2026-09-25T10:21:51Z
Modified
2026-09-26T03:48:27Z
Summary
smb: client: reject userspace cifs.idmap descriptions
Details

In the Linux kernel, the following vulnerability has been resolved:

smb: client: reject userspace cifs.idmap descriptions

cifs.idmap key descriptions carry authority-bearing fields (owner and group SIDs and uid/gid values in "os:"/"gs:"/"oi:"/"gi:" form) that the cifs.idmap upcall helper treats as kernel-originating inputs. Unlike its sibling cifs.spnego, the cifs.idmap key type has no vet_description hook, so userspace can create keys of this type through request_key(2)/add_key(2) and supply those fields without CIFS origin. A request_key(2) call with a non-NULL callout then drives a root usermodehelper upcall (/sbin/request-key -> cifs.idmap) that consumes the unvetted description in root context.

Only accept cifs.idmap descriptions while CIFS is using its private root_cred to request the key. id_to_sid()/sid_to_id() already run under override_creds(root_cred), so the kernel-originated path is unaffected.

This mirrors commit 3da1fdf4efbc ("smb: client: reject userspace cifs.spnego descriptions"), which applied the same restriction to cifs.spnego.

Database specific
{
    "cna_assigner":  "Linux",
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/97xxx/CVE-2026-97564.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
4d79dba0e00749fa40de8ef13a9b85ce57a1603b
Fixed
e5964064e3fbe6325893408faff08ca33de0e2c3
Fixed
96751028c0d4dec785709ea3eb0ab38a4f2ded96
Fixed
1d3b24b16a0b013792e8f1e3ed060f0b46f537d1
Fixed
d9d7eeb0cea5b55b82888f443622fd8d4ee064f3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-97564.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.0.0
Fixed
6.12.111
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.53
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.7

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-97564.json"