PT-2026-104858 · Azure Linux · Kernel

Published

2026-09-24

·

Updated

2026-09-24

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: fix maximum allowed access checks
The DACL permission check looks for an ACE matching the current user and falls back to the Everyone ACE. It does not consider an Authenticated Users ACE, even though an authenticated session is a member of that well-known group.
As a result, opening a file whose access is granted through S-1-5-11 can incorrectly fail with STATUS ACCESS DENIED. Treat an Authenticated Users ACE as a fallback entry alongside Everyone.
The maximal access calculation also combines access masks from every ACE, regardless of whether its SID applies to the current user. This can grant rights belonging to an unrelated principal. Process only ACEs applying to the user, Everyone, or Authenticated Users, and accumulate allowed and denied masks in ACL order. Preserve explicitly requested access bits so they are validated against the resulting maximal mask.
When ACCESS SYSTEM SECURITY is denied, report STATUS PRIVILEGE NOT HELD instead of the generic STATUS ACCESS DENIED. Access to the system ACL requires a security privilege that ksmbd does not grant.
For regular files, include FILE EXECUTE in maximal access when the client requested GENERIC EXECUTE and the DACL grants the complete file-read set. Keep a direct FILE EXECUTE request subject to the explicit DACL bit. This matches the POSIX file ACL mapping without broadening specific execute requests.
Do not replace rights from an applicable NT ACE with a POSIX ACL entry. The POSIX ACL is only a fallback when no user, Everyone, or Authenticated Users ACE applies; otherwise it can incorrectly broaden the stored DACL.
This fixes smb2.maximum allowed.maximum allowed.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-103583

Affected Products

Kernel