PT-2026-97969 · Linux · Linux Kernel

CVE-2026-93282

·

Published

2026-09-24

·

Updated

2026-09-28

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the ksmbd module regarding maximum allowed access checks. The DACL (Discretionary Access Control List) permission check fails to consider the Authenticated Users ACE (Access Control Entry), causing file access granted via S-1-5-11 to incorrectly return STATUS ACCESS DENIED. Additionally, the maximal access calculation incorrectly combines access masks from every ACE regardless of whether the SID (Security Identifier) applies to the current user, potentially granting rights belonging to unrelated principals. The system also incorrectly reports STATUS ACCESS DENIED instead of STATUS PRIVILEGE NOT HELD when ACCESS SYSTEM SECURITY is denied. Furthermore, the logic for handling FILE EXECUTE requests and the fallback mechanism for POSIX ACL entries could incorrectly broaden the stored DACL if NT ACE rights are replaced. The flaw is located in the smb2.maximum allowed.maximum allowed function.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-93282
OPENSUSE-SU-2026:11893-1

Affected Products

Linux Kernel