HIGH Introduced in 5.15
ksmbd PosixAcl Bypass
CVE-2026-93786
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
KernelScan AI8.6HIGH
01Description
In the Linux kernel, the following vulnerability has been resolved: ksmbd: preserve VFS inherited POSIX ACL mask The VFS initializes a child's POSIX ACL from the parent's default ACL and the requested creation mode. Do not mutate the parent ACL or overwrite the child's VFS-computed access and default ACLs afterwards. This preserves restrictive ACL_MASK entries and prevents SMB object creation from widening effective permissions.
02KernelScan AI Analysis
Risk summary
The kernel's in-kernel SMB server widens POSIX ACL permissions when creating files and directories via SMB, overriding restrictive ACL masks that the VFS had already computed. Any authenticated SMB client with create permissions on an exported share can trigger this, potentially allowing other users on the system to read or modify files they should not have access to. Systems running ksmbd with multiple users or tenants sharing filesystems are most at risk.
Vulnerability analysis
When an SMB client creates a file or directory through ksmbd, the server retrieves the parent directory's default POSIX ACL, overwrites the ACL_MASK entry with full read-write-execute permissions, and applies this modified ACL to the newly created object—overriding the permissions the VFS had already computed from the parent's default ACL and the requested creation mode. This means objects created via SMB can end up with broader effective permissions than intended, potentially giving other users on the system access to files they should not see or modify. The fix removes the ACL mutation and overwriting code entirely, letting the VFS's own ACL inheritance computation stand without interference. The vulnerability is reachable by any authenticated SMB client who can create objects on an exported share; it requires no special host-level privileges beyond SMB access, and the ksmbd service must be running and network-reachable.
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| 6.12 | 5.15 | 6.12.111 | 591acf171644 |
| 6.18 | 5.15 | 6.18.53 | 0093909becbd |
| mainline | 5.15 | 7.2 | e148e567a925 |