CVE-2026-98114EPSS p5.4%
CVE-2026-98114CVE-2026-98114
Description
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: propagate DACL parsing errors
parse_dacl() silently accepts truncated ACEs and allocation failures,
allowing set_info_sec() to continue with an incomplete ACL conversion.
Return parsing and allocation errors to parse_sec_desc() so malformed
security descriptors are rejected before inode attributes or ACL xattrs
are updated.
Scoring
| EPSS | 0.17% probability of exploitation · percentile 5.4% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-30 |