{"api_version":"1","generated_at":"2026-10-01T11:59:20+00:00","cve":"CVE-2026-93282","urls":{"html":"https://cve.report/CVE-2026-93282","api":"https://cve.report/api/cve/CVE-2026-93282.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-93282","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-93282"},"summary":{"title":"ksmbd: fix maximum allowed access checks","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: fix maximum allowed access checks\n\nThe DACL permission check looks for an ACE matching the current user and\nfalls back to the Everyone ACE. It does not consider an Authenticated\nUsers ACE, even though an authenticated session is a member of that\nwell-known group.\n\nAs a result, opening a file whose access is granted through S-1-5-11 can\nincorrectly fail with STATUS_ACCESS_DENIED. Treat an Authenticated Users\nACE as a fallback entry alongside Everyone.\n\nThe maximal access calculation also combines access masks from every ACE,\nregardless of whether its SID applies to the current user. This can grant\nrights belonging to an unrelated principal. Process only ACEs applying to\nthe user, Everyone, or Authenticated Users, and accumulate allowed and\ndenied masks in ACL order. Preserve explicitly requested access bits so\nthey are validated against the resulting maximal mask.\n\nWhen ACCESS_SYSTEM_SECURITY is denied, report STATUS_PRIVILEGE_NOT_HELD\ninstead of the generic STATUS_ACCESS_DENIED. Access to the system ACL\nrequires a security privilege that ksmbd does not grant.\n\nFor regular files, include FILE_EXECUTE in maximal access when the client\nrequested GENERIC_EXECUTE and the DACL grants the complete file-read set.\nKeep a direct FILE_EXECUTE request subject to the explicit DACL bit. This\nmatches the POSIX file ACL mapping without broadening specific execute\nrequests.\n\nDo not replace rights from an applicable NT ACE with a POSIX ACL entry.\nThe POSIX ACL is only a fallback when no user, Everyone, or Authenticated\nUsers ACE applies; otherwise it can incorrectly broaden the stored DACL.\n\nThis fixes smb2.maximum_allowed.maximum_allowed.","state":"PUBLISHED","assigner":"Linux","published_at":"2026-09-24 16:17:25","updated_at":"2026-09-25 13:17:18"},"problem_types":[],"metrics":[{"version":"3.1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","score":"8.1","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"8.1","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","data":{"baseScore":8.1,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","version":"3.1"}}],"references":[{"url":"https://git.kernel.org/stable/c/35d5c59fe6b1d9fe43fb14eb384f69ee1a120f9c","name":"https://git.kernel.org/stable/c/35d5c59fe6b1d9fe43fb14eb384f69ee1a120f9c","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/cc2f133e80eb2c4a04bfa77a2f207749fe2f516a","name":"https://git.kernel.org/stable/c/cc2f133e80eb2c4a04bfa77a2f207749fe2f516a","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-93282","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-93282","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 35d5c59fe6b1d9fe43fb14eb384f69ee1a120f9c git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 cc2f133e80eb2c4a04bfa77a2f207749fe2f516a git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 5.15","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 5.15 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2.6 7.2.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.3-rc1 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"93282","cve":"CVE-2026-93282","epss":"0.003080000","percentile":"0.211400000","score_date":"2026-09-27","updated_at":"2026-09-28 00:02:24"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["fs/smb/server/smb2pdu.c","fs/smb/server/smbacl.c","fs/smb/server/smbacl.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"35d5c59fe6b1d9fe43fb14eb384f69ee1a120f9c","status":"affected","version":"e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9","versionType":"git"},{"lessThan":"cc2f133e80eb2c4a04bfa77a2f207749fe2f516a","status":"affected","version":"e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["fs/smb/server/smb2pdu.c","fs/smb/server/smbacl.c","fs/smb/server/smbacl.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"5.15"},{"lessThan":"5.15","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"7.2.*","status":"unaffected","version":"7.2.6","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.3-rc1","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2.6","versionStartIncluding":"5.15","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.3-rc1","versionStartIncluding":"5.15","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: fix maximum allowed access checks\n\nThe DACL permission check looks for an ACE matching the current user and\nfalls back to the Everyone ACE. It does not consider an Authenticated\nUsers ACE, even though an authenticated session is a member of that\nwell-known group.\n\nAs a result, opening a file whose access is granted through S-1-5-11 can\nincorrectly fail with STATUS_ACCESS_DENIED. Treat an Authenticated Users\nACE as a fallback entry alongside Everyone.\n\nThe maximal access calculation also combines access masks from every ACE,\nregardless of whether its SID applies to the current user. This can grant\nrights belonging to an unrelated principal. Process only ACEs applying to\nthe user, Everyone, or Authenticated Users, and accumulate allowed and\ndenied masks in ACL order. Preserve explicitly requested access bits so\nthey are validated against the resulting maximal mask.\n\nWhen ACCESS_SYSTEM_SECURITY is denied, report STATUS_PRIVILEGE_NOT_HELD\ninstead of the generic STATUS_ACCESS_DENIED. Access to the system ACL\nrequires a security privilege that ksmbd does not grant.\n\nFor regular files, include FILE_EXECUTE in maximal access when the client\nrequested GENERIC_EXECUTE and the DACL grants the complete file-read set.\nKeep a direct FILE_EXECUTE request subject to the explicit DACL bit. This\nmatches the POSIX file ACL mapping without broadening specific execute\nrequests.\n\nDo not replace rights from an applicable NT ACE with a POSIX ACL entry.\nThe POSIX ACL is only a fallback when no user, Everyone, or Authenticated\nUsers ACE applies; otherwise it can incorrectly broaden the stored DACL.\n\nThis fixes smb2.maximum_allowed.maximum_allowed."}],"metrics":[{"cvssV3_1":{"baseScore":8.1,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","version":"3.1"},"scenarios":[{"lang":"en","value":"AV:N - SMB2_CREATE carries req->DesiredAccess into smb2_open(), which calls smb_check_perm_dacl() on the NT DACL from ksmbd_vfs_get_sd_xattr(); ksmbd_conn_handler_loop() delivers that CREATE on TCP/445 through __handle_ksmbd_work() after smb2_check_user_session()/smb2_get_ksmbd_tcon().\nAC:L - With FILE_MAXIMAL_ACCESS_LE set, smb_check_perm_dacl() does granted |= ace->access_req for every ACE regardless of SID, and when the user SID is not found it applies a POSIX ACL_USER/ACL_GROUP entry even if an Everyone ACE exists; one attacker-sent SMB2_CREATE triggers that with no race.\nPR:L - SMB2_CREATE is not in the smb2_check_user_session() pre-auth skip list (only NEGOTIATE/SESSION_SETUP/ECHO); __handle_ksmbd_work() requires SMB2_SESSION_VALID and smb2_get_ksmbd_tcon() before smb2_open(), so this is an authenticated share user, not a pre-auth or host-root path.\nUI:N - The attacker sends the SMB2_CREATE that smb2_open() uses to call smb_check_perm_dacl() on a file they name; no victim mount, click, or other interactive step is required.\nS:U - smb_check_perm_dacl() only miscomputes the access mask stored as fp->daccess for that ksmbd open; the extra rights stay inside the host kernel SMB server and do not cross a VM, IOMMU, or sandbox boundary.\nC:H - When FILE_MAXIMAL_ACCESS_LE is set, granted ORs access_req from unrelated SIDs, and a POSIX ACL_USER match can replace a tighter Everyone ACE; *pdaccess becomes fp->daccess, so smb2_read() seeing FILE_READ_DATA_LE returns file contents the stored DACL would have denied with -EACCES.\nI:H - The same inflated mask can include FILE_WRITE_DATA, WRITE_DAC, or DELETE from another principal's ACE or from mode_to_access_flags() on a POSIX rwx/r-- entry; smb2_write(), smb2_set_info_sec(), and set_file_disposition_info() then allow writes, DACL replacement, or deletes the stored DACL would have rejected.\nA:N - smb_check_perm_dacl() only returns 0 with a wider granted mask or -EACCES mapped to STATUS_ACCESS_DENIED/STATUS_PRIVILEGE_NOT_HELD; the ACE walks stay inside the NTSD and do not oops, panic, hang, or crash ksmbd."}]}],"providerMetadata":{"dateUpdated":"2026-09-25T12:42:44.106Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/35d5c59fe6b1d9fe43fb14eb384f69ee1a120f9c"},{"url":"https://git.kernel.org/stable/c/cc2f133e80eb2c4a04bfa77a2f207749fe2f516a"}],"title":"ksmbd: fix maximum allowed access checks","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-93282","datePublished":"2026-09-24T15:52:24.603Z","dateReserved":"2026-09-17T16:02:15.098Z","dateUpdated":"2026-09-25T12:42:44.106Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-24 16:17:25","lastModifiedDate":"2026-09-25 13:17:18","problem_types":[],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":5.2}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"93282","Ordinal":"1","Title":"ksmbd: fix maximum allowed access checks","CVE":"CVE-2026-93282","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"93282","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: fix maximum allowed access checks\n\nThe DACL permission check looks for an ACE matching the current user and\nfalls back to the Everyone ACE. It does not consider an Authenticated\nUsers ACE, even though an authenticated session is a member of that\nwell-known group.\n\nAs a result, opening a file whose access is granted through S-1-5-11 can\nincorrectly fail with STATUS_ACCESS_DENIED. Treat an Authenticated Users\nACE as a fallback entry alongside Everyone.\n\nThe maximal access calculation also combines access masks from every ACE,\nregardless of whether its SID applies to the current user. This can grant\nrights belonging to an unrelated principal. Process only ACEs applying to\nthe user, Everyone, or Authenticated Users, and accumulate allowed and\ndenied masks in ACL order. Preserve explicitly requested access bits so\nthey are validated against the resulting maximal mask.\n\nWhen ACCESS_SYSTEM_SECURITY is denied, report STATUS_PRIVILEGE_NOT_HELD\ninstead of the generic STATUS_ACCESS_DENIED. Access to the system ACL\nrequires a security privilege that ksmbd does not grant.\n\nFor regular files, include FILE_EXECUTE in maximal access when the client\nrequested GENERIC_EXECUTE and the DACL grants the complete file-read set.\nKeep a direct FILE_EXECUTE request subject to the explicit DACL bit. This\nmatches the POSIX file ACL mapping without broadening specific execute\nrequests.\n\nDo not replace rights from an applicable NT ACE with a POSIX ACL entry.\nThe POSIX ACL is only a fallback when no user, Everyone, or Authenticated\nUsers ACE applies; otherwise it can incorrectly broaden the stored DACL.\n\nThis fixes smb2.maximum_allowed.maximum_allowed.","Type":"Description","Title":"ksmbd: fix maximum allowed access checks"}]}}}