Linux Kernel Vulnerability Affecting ksmbd Functionality
CVE-2026-93282

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
24 September 2026

What is CVE-2026-93282?

A vulnerability in the ksmbd component of the Linux kernel allows improper handling of access control lists (ACL), specifically regarding permission checks for authenticated users. This oversight may result in unexpected access denials when users should have been granted appropriate access rights based on specified permissions. The ACL calculations fail to properly account for the 'Authenticated Users' group, leading to potential access issues even when valid permissions are in place. This flaw necessitates that ACL entries for users, 'Everyone', and 'Authenticated Users' are individually validated to prevent incorrect privilege escalations or access denials. Correct handling of ACL entries is critical to maintain consistent and secure file access controls within systems relying on ksmbd.

Affected Version(s)

Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 35d5c59fe6b1d9fe43fb14eb384f69ee1a120f9c

Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2

Linux 0 < 7.2.6

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.