Incorrect permission assignment for critical resource in Linux kernel - CVE-2026-93786
Published: September 25, 2026
Vulnerability details
The vulnerability allows a remote user to widen effective permissions on SMB-created objects.
The vulnerability exists due to improper permission assignment in the ksmbd VFS POSIX ACL inheritance handling when creating SMB objects in directories with default POSIX ACLs. A remote user can create an SMB object to widen effective permissions on that object.
Exploitation requires a parent directory with a default POSIX ACL containing a restrictive ACL_MASK entry.