smack: fix incorrect task context in smack_msg_queue_msgrcv
Summary
| CVE | CVE-2026-93191 |
|---|---|
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-17 17:18:15 UTC |
| Updated | 2026-09-17 17:18:15 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved: smack: fix incorrect task context in smack_msg_queue_msgrcv The smack_msg_queue_msgrcv() function incorrectly checks the permissions of the 'current' task instead of the 'target' task. In the msgsnd() syscall path, if a receiver is already waiting, the pipelined_send() optimization is used to push the message directly to the receiver task: ipc/msg.c`pipelined_send(): ` smp_store_release(&msr->r_msg, msg) In this case, the 'sender' (current) task performs the check on behalf of the 'receiver' task (msr->r_tsk, passed as the 'target' parameter): ipc/msg.c`pipelined_send(): ` security_msg_queue_msgrcv(,, target := msr->r_tsk,,) However, smack_msg_queue_msgrcv() ignores the 'target' and checks 'current': smack_msg_queue_msgrcv(…) ` smk_curacc_msq(isp, MAY_READWRITE); // current task 'current' MAY satisfy smack_msg_queue_msgrcv r/w requirement, but 'target' (the receiver task) might NOT; as a result, an unauthorized receiver gets the message, violating MAC policy. Test: 1) create a sysv message queue with label “foo” 2) echo "bar foo r" >/smack/load2 3) msgrcv(,,,0,MSG_NOERROR) in "bar"-labeled task. The task is waiting for the messages ... 4) msgsnd() from a "foo"-labeled task: "bar"-labeled task gets the message. This patch fixes the issue by checking permission on the 'target' task instead of 'current'. (2008-02-04, Casey Schaufler) |
Risk And Classification
EPSS: 0.001960000 probability, percentile 0.096460000 (date 2026-09-19)
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Linux | affected e114e473771c848c3cfec05f0123e70f1cdbdc99 4e49f997ef0c569e09b42aab6bd38c7c54ea095d git | Not specified |
| CNA | Linux | Linux | affected e114e473771c848c3cfec05f0123e70f1cdbdc99 dbece6c2f80b0470d8d99d7a016827dce99ed6e3 git | Not specified |
| CNA | Linux | Linux | affected e114e473771c848c3cfec05f0123e70f1cdbdc99 7be4bd21c50afa83c93799b0f16cf5bfa493194e git | Not specified |
| CNA | Linux | Linux | affected e114e473771c848c3cfec05f0123e70f1cdbdc99 ec47f4177046dfaaf1cebb15f4d2e7b543475daf git | Not specified |
| CNA | Linux | Linux | affected e114e473771c848c3cfec05f0123e70f1cdbdc99 e35dc5a4ed6d1e536382d80c685187511ff248a1 git | Not specified |
| CNA | Linux | Linux | affected e114e473771c848c3cfec05f0123e70f1cdbdc99 c2ab27c2e11591524b1378c24ad18882a425d1fa git | Not specified |
| CNA | Linux | Linux | affected e114e473771c848c3cfec05f0123e70f1cdbdc99 d02c55e3ea82e41ea2c2026e08201e5daa4d0cfe git | Not specified |
| CNA | Linux | Linux | affected e114e473771c848c3cfec05f0123e70f1cdbdc99 fba3d32825f4bbc8e20f0cdc3b14df57965b8fe5 git | Not specified |
| CNA | Linux | Linux | affected 2.6.25 | Not specified |
| CNA | Linux | Linux | unaffected 2.6.25 semver | Not specified |
| CNA | Linux | Linux | unaffected 5.10.270 5.10.* semver | Not specified |
| CNA | Linux | Linux | unaffected 5.15.221 5.15.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.1.188 6.1.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.6.157 6.6.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.12.110 6.12.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.18.52 6.18.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.2.6 7.2.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.3-rc1 * original_commit_for_fix | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| git.kernel.org/stable/c/dbece6c2f80b0470d8d99d7a016827dce99ed6e3 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/7be4bd21c50afa83c93799b0f16cf5bfa493194e | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/4e49f997ef0c569e09b42aab6bd38c7c54ea095d | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/ec47f4177046dfaaf1cebb15f4d2e7b543475daf | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/fba3d32825f4bbc8e20f0cdc3b14df57965b8fe5 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/d02c55e3ea82e41ea2c2026e08201e5daa4d0cfe | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/c2ab27c2e11591524b1378c24ad18882a425d1fa | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/e35dc5a4ed6d1e536382d80c685187511ff248a1 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.