SB2026092597 - Improper access control in Linux kernel smb server
Published: September 25, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper access control (CVE-ID: CVE-2026-93282)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to obtain unauthorized file access rights.
The vulnerability exists due to improper access control in the ksmbd DACL maximum access calculation when processing SMB2 open requests that request maximal access. A remote user can request maximal access to a file to obtain unauthorized file access rights.
Remediation
Install update from vendor's website.