Improper access control in Linux kernel - CVE-2026-52906
Published: June 10, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to bypass privileged file operations on a mounted 9p filesystem.
The vulnerability exists due to improper access control in v9fs_apply_options() and v9fs_fid_lookup() when processing mount access mode options. A local user can mount the filesystem with the "access=user" option to cause fid lookups to use INVALID_UID instead of current_fsuid().
This issue affects 9P2000.L mounts because conflicting access mode bits can be set at the same time, causing access mode checks to match neither mode.