PT-2026-97986 · Linux · Linux Kernel

CVE-2026-93786

·

Published

2026-09-24

·

Updated

2026-09-25

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the ksmbd module where the Virtual File System (VFS) initializes a child's POSIX Access Control List (ACL) using the parent's default ACL and the requested creation mode. The system fails to preserve the restrictive ACL MASK entries, which can allow SMB object creation to widen effective permissions by mutating the parent ACL or overwriting the VFS-computed access and default ACLs.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-93786

Affected Products

Linux Kernel