← All Advisories

CVE-2026-93282

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-93282

Key Details

CVECVE-2026-93282
CVSS Score / Version8.1 (High) / CVSS v3.1
Updated2026-09-25
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
CVSS Proseattack vector is network; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is none.
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

ksmbd: fix maximum allowed access checks

The DACL permission check looks for an ACE matching the current user and

falls back to the Everyone ACE. It does not consider an Authenticated

Users ACE, even though an authenticated session is a member of that

well-known group.

As a result, opening a file whose access is granted through S-1-5-11 can

incorrectly fail with STATUS_ACCESS_DENIED. Treat an Authenticated Users

ACE as a fallback entry alongside Everyone.

The maximal access calculation also combines access masks from every ACE,

regardless of whether its SID applies to the current user. This can grant

rights belonging to an unrelated principal. Process only ACEs applying to

the user, Everyone, or Authenticated Users, and accumulate allowed and

denied masks in ACL order. Preserve explicitly requested access bits so

they are validated against the resulting maximal mask.

When ACCESS_SYSTEM_SECURITY is denied, report STATUS_PRIVILEGE_NOT_HELD

instead of the generic STATUS_ACCESS_DENIED. Access to the system ACL

requires a security privilege that ksmbd does not grant.

For regular files, include FILE_EXECUTE in maximal access when the client

requested GENERIC_EXECUTE and the DACL grants the complete file-read set.

Keep a direct FILE_EXECUTE request subject to the explicit DACL bit. This

matches the POSIX file ACL mapping without broadening specific execute

requests.

Do not replace rights from an applicable NT ACE with a POSIX ACL entry.

The POSIX ACL is only a fallback when no user, Everyone, or Authenticated

Users ACE applies; otherwise it can incorrectly broaden the stored DACL.

This fixes smb2.maximum_allowed.maximum_allowed. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-93282
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-93282