What is CVE-2026-68099?
This vulnerability in the Linux kernel's `ksmbd` module occurs due to a malformed `DACL` caused by the `check_add_overflow()` function incorrectly writing a truncated sum on overflow. This can lead to improper handling of access control lists, potentially resulting in privilege escalation. It is recommended to update to the latest stable kernel version.
Azərbaycanca: Linux kernel-də `ksmbd` (Kernel SMB server) modulunda aşkar edilmiş bu boşluq, `check_add_overflow()` funksiyasının hesablama zamanı əmələ gətirdiyi malformed `DACL` (Discretionary Access Control List) səbəbindən yaranır. Bu zəiflik, `d` dəyişəninin ölçüsünün daşma nəticəsində səhv yazılmasına gətirib çıxarır və potensial olaraq imtiyaz yüksəlişi ilə nəticələnə bilər. Kernel-i ən son stabil versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-190
FAQ2
In which module of the Linux kernel was CVE-2026-68099 discovered?
This vulnerability was discovered in the `ksmbd` (Kernel SMB server) module of the Linux kernel.
What is the potential impact if CVE-2026-68099 is exploited?
It can potentially result in privilege escalation.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.