KernelScan.io

HIGH Introduced in 5.15

ksmbd MaximalAccess Bypass

CVE-2026-93282

CVSS 8.1 / 10.0 NVD

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

KernelScan AI8.0HIGH

01

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix maximum allowed access checks The DACL permission check looks for an ACE matching the current user and falls back to the Everyone ACE. It does not consider an Authenticated Users ACE, even though an authenticated session is a member of that well-known group. As a result, opening a file whose access is granted through S-1-5-11 can incorrectly fail with STATUS_ACCESS_DENIED. Treat an Authenticated Users ACE as a fallback entry alongside Everyone. The maximal access calculation also combines access masks from every ACE, regardless of whether its SID applies to the current user. This can grant rights belonging to an unrelated principal. Process only ACEs applying to the user, Everyone, or Authenticated Users, and accumulate allowed and denied masks in ACL order. Preserve explicitly requested access bits so they are validated against the resulting maximal mask. When ACCESS_SYSTEM_SECURITY is denied, report STATUS_PRIVILEGE_NOT_HELD instead of the generic STATUS_ACCESS_DENIED. Access to the system ACL requires a security privilege that ksmbd does not grant. For regular files, include FILE_EXECUTE in maximal access when the client requested GENERIC_EXECUTE and the DACL grants the complete file-read set. Keep a direct FILE_EXECUTE request subject to the explicit DACL bit. This matches the POSIX file ACL mapping without broadening specific execute requests. Do not replace rights from an applicable NT ACE with a POSIX ACL entry. The POSIX ACL is only a fallback when no user, Everyone, or Authenticated Users ACE applies; otherwise it can incorrectly broaden the stored DACL. This fixes smb2.maximum_allowed.maximum_allowed.

02

Engine v0.6.0

Risk summary

Systems running the ksmbd in-kernel SMB server are at risk. An authenticated SMB client can gain unauthorized read, write, or delete access to shared files because the maximal-access calculation combines permission masks from every ACL entry regardless of which principal they apply to. This enables cross-user file access violations across all exported shares.

Affectedfs/smb/server/smbacl.c (ksmbd)

Vulnerability analysis

When an SMB client requests the maximum allowed access for a file, the ksmbd server iterates over every access control entry in the file's discretionary ACL and combines all permission masks together without checking whether each entry's security identifier actually applies to the requesting user. This grants the caller the union of every principal's rights, letting any authenticated session receive permissions belonging to unrelated users. The fix processes only entries matching the current user, Everyone, or Authenticated Users, accumulates allowed and denied masks in ACL order, and validates explicitly requested access bits against the resulting mask. It also stops falling back to POSIX ACL entries when an applicable NT ACE already exists, preventing the stored DACL from being silently broadened. An attacker needs only an authenticated SMB session to trigger this over the network; the impact is unauthorized read, write, or delete access to any file the server exports.

03

BranchIntroducedFixed inPatch commit
7.25.157.2.635d5c59fe6b1
mainline5.157.3-rc1cc2f133e80eb