Improper access control in Linux kernel - CVE-2026-52906

 

Improper access control in Linux kernel - CVE-2026-52906

Published: June 10, 2026


Vulnerability identifier: #VU134163
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-52906
CWE-ID: CWE-284
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to bypass privileged file operations on a mounted 9p filesystem.

The vulnerability exists due to improper access control in v9fs_apply_options() and v9fs_fid_lookup() when processing mount access mode options. A local user can mount the filesystem with the "access=user" option to cause fid lookups to use INVALID_UID instead of current_fsuid().

This issue affects 9P2000.L mounts because conflicting access mode bits can be set at the same time, causing access mode checks to match neither mode.


Affected software

Linux kernel
Ubuntu
linux (Ubuntu package)
linux-azure (Ubuntu package)
linux-nvidia (Ubuntu package)
linux-raspi (Ubuntu package)

How to mitigate CVE-2026-52906

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3
linux (Ubuntu package) - update to 7.0.0-27.27
linux-azure (Ubuntu package) - addressed in versions 7.0.0-1009.9, 7.0.0-1010.10
linux-nvidia (Ubuntu package) - update to 7.0.0-1013.13
linux-raspi (Ubuntu package) - update to 7.0.0-1014.14

External References

Related Security Bulletins