smack: fix incorrect task context in smack_msg_queue_msgrcv

Summary

CVECVE-2026-93191
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2026-09-17 17:18:15 UTC
Updated2026-09-17 17:18:15 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: smack: fix incorrect task context in smack_msg_queue_msgrcv The smack_msg_queue_msgrcv() function incorrectly checks the permissions of the 'current' task instead of the 'target' task. In the msgsnd() syscall path, if a receiver is already waiting, the pipelined_send() optimization is used to push the message directly to the receiver task: ipc/msg.c`pipelined_send(): ` smp_store_release(&msr->r_msg, msg) In this case, the 'sender' (current) task performs the check on behalf of the 'receiver' task (msr->r_tsk, passed as the 'target' parameter): ipc/msg.c`pipelined_send(): ` security_msg_queue_msgrcv(,, target := msr->r_tsk,,) However, smack_msg_queue_msgrcv() ignores the 'target' and checks 'current': smack_msg_queue_msgrcv(…) ` smk_curacc_msq(isp, MAY_READWRITE); // current task 'current' MAY satisfy smack_msg_queue_msgrcv r/w requirement, but 'target' (the receiver task) might NOT; as a result, an unauthorized receiver gets the message, violating MAC policy. Test: 1) create a sysv message queue with label “foo” 2) echo "bar foo r" >/smack/load2 3) msgrcv(,,,0,MSG_NOERROR) in "bar"-labeled task. The task is waiting for the messages ... 4) msgsnd() from a "foo"-labeled task: "bar"-labeled task gets the message. This patch fixes the issue by checking permission on the 'target' task instead of 'current'. (2008-02-04, Casey Schaufler)

Risk And Classification

EPSS: 0.001960000 probability, percentile 0.096460000 (date 2026-09-19)

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected e114e473771c848c3cfec05f0123e70f1cdbdc99 4e49f997ef0c569e09b42aab6bd38c7c54ea095d git Not specified
CNA Linux Linux affected e114e473771c848c3cfec05f0123e70f1cdbdc99 dbece6c2f80b0470d8d99d7a016827dce99ed6e3 git Not specified
CNA Linux Linux affected e114e473771c848c3cfec05f0123e70f1cdbdc99 7be4bd21c50afa83c93799b0f16cf5bfa493194e git Not specified
CNA Linux Linux affected e114e473771c848c3cfec05f0123e70f1cdbdc99 ec47f4177046dfaaf1cebb15f4d2e7b543475daf git Not specified
CNA Linux Linux affected e114e473771c848c3cfec05f0123e70f1cdbdc99 e35dc5a4ed6d1e536382d80c685187511ff248a1 git Not specified
CNA Linux Linux affected e114e473771c848c3cfec05f0123e70f1cdbdc99 c2ab27c2e11591524b1378c24ad18882a425d1fa git Not specified
CNA Linux Linux affected e114e473771c848c3cfec05f0123e70f1cdbdc99 d02c55e3ea82e41ea2c2026e08201e5daa4d0cfe git Not specified
CNA Linux Linux affected e114e473771c848c3cfec05f0123e70f1cdbdc99 fba3d32825f4bbc8e20f0cdc3b14df57965b8fe5 git Not specified
CNA Linux Linux affected 2.6.25 Not specified
CNA Linux Linux unaffected 2.6.25 semver Not specified
CNA Linux Linux unaffected 5.10.270 5.10.* semver Not specified
CNA Linux Linux unaffected 5.15.221 5.15.* semver Not specified
CNA Linux Linux unaffected 6.1.188 6.1.* semver Not specified
CNA Linux Linux unaffected 6.6.157 6.6.* semver Not specified
CNA Linux Linux unaffected 6.12.110 6.12.* semver Not specified
CNA Linux Linux unaffected 6.18.52 6.18.* semver Not specified
CNA Linux Linux unaffected 7.2.6 7.2.* semver Not specified
CNA Linux Linux unaffected 7.3-rc1 * original_commit_for_fix Not specified

References

ReferenceSourceLinkTags
git.kernel.org/stable/c/dbece6c2f80b0470d8d99d7a016827dce99ed6e3 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/7be4bd21c50afa83c93799b0f16cf5bfa493194e 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/4e49f997ef0c569e09b42aab6bd38c7c54ea095d 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/ec47f4177046dfaaf1cebb15f4d2e7b543475daf 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/fba3d32825f4bbc8e20f0cdc3b14df57965b8fe5 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/d02c55e3ea82e41ea2c2026e08201e5daa4d0cfe 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/c2ab27c2e11591524b1378c24ad18882a425d1fa 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/e35dc5a4ed6d1e536382d80c685187511ff248a1 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report