SB2026091817 - Incorrect authorization in Linux kernel smack
Published: September 18, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Incorrect authorization (CVE-ID: CVE-2026-93191)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose messages to an unauthorized receiver.
The vulnerability exists due to improper authorization in smack_msg_queue_msgrcv when processing messages through the pipelined_send optimization for a waiting receiver. A local user can send a message to a queue while an unauthorized target task is waiting to receive it to disclose messages to an unauthorized receiver.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/4e49f997ef0c569e09b42aab6bd38c7c54ea095d
- https://git.kernel.org/stable/c/7be4bd21c50afa83c93799b0f16cf5bfa493194e
- https://git.kernel.org/stable/c/c2ab27c2e11591524b1378c24ad18882a425d1fa
- https://git.kernel.org/stable/c/d02c55e3ea82e41ea2c2026e08201e5daa4d0cfe
- https://git.kernel.org/stable/c/dbece6c2f80b0470d8d99d7a016827dce99ed6e3
- https://git.kernel.org/stable/c/e35dc5a4ed6d1e536382d80c685187511ff248a1
- https://git.kernel.org/stable/c/ec47f4177046dfaaf1cebb15f4d2e7b543475daf
- https://git.kernel.org/stable/c/fba3d32825f4bbc8e20f0cdc3b14df57965b8fe5