SB2026092597 - Improper access control in Linux kernel smb server



SB2026092597 - Improper access control in Linux kernel smb server

Published: September 25, 2026

Security Bulletin ID SB2026092597
CSH Severity
High
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Improper access control (CVE-ID: CVE-2026-93282)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to obtain unauthorized file access rights.

The vulnerability exists due to improper access control in the ksmbd DACL maximum access calculation when processing SMB2 open requests that request maximal access. A remote user can request maximal access to a file to obtain unauthorized file access rights.


Remediation

Install update from vendor's website.