Linux Kernel Vulnerability Affecting ksmbd Functionality
CVE-2026-93282
What is CVE-2026-93282?
A vulnerability in the ksmbd component of the Linux kernel allows improper handling of access control lists (ACL), specifically regarding permission checks for authenticated users. This oversight may result in unexpected access denials when users should have been granted appropriate access rights based on specified permissions. The ACL calculations fail to properly account for the 'Authenticated Users' group, leading to potential access issues even when valid permissions are in place. This flaw necessitates that ACL entries for users, 'Everyone', and 'Authenticated Users' are individually validated to prevent incorrect privilege escalations or access denials. Correct handling of ACL entries is critical to maintain consistent and secure file access controls within systems relying on ksmbd.
Affected Version(s)
Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 35d5c59fe6b1d9fe43fb14eb384f69ee1a120f9c
Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Linux 0 < 7.2.6