PT-2026-97969 · Linux · Linux Kernel
CVE-2026-93282
·
Published
2026-09-24
·
Updated
2026-09-28
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
An issue exists in the
ksmbd module regarding maximum allowed access checks. The DACL (Discretionary Access Control List) permission check fails to consider the Authenticated Users ACE (Access Control Entry), causing file access granted via S-1-5-11 to incorrectly return STATUS ACCESS DENIED. Additionally, the maximal access calculation incorrectly combines access masks from every ACE regardless of whether the SID (Security Identifier) applies to the current user, potentially granting rights belonging to unrelated principals. The system also incorrectly reports STATUS ACCESS DENIED instead of STATUS PRIVILEGE NOT HELD when ACCESS SYSTEM SECURITY is denied. Furthermore, the logic for handling FILE EXECUTE requests and the fallback mechanism for POSIX ACL entries could incorrectly broaden the stored DACL if NT ACE rights are replaced. The flaw is located in the smb2.maximum allowed.maximum allowed function.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel