Improper access control in Linux kernel - CVE-2026-93282

 

Improper access control in Linux kernel - CVE-2026-93282

Published: September 25, 2026


Vulnerability identifier: #VU152121
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-93282
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to obtain unauthorized file access rights.

The vulnerability exists due to improper access control in the ksmbd DACL maximum access calculation when processing SMB2 open requests that request maximal access. A remote user can request maximal access to a file to obtain unauthorized file access rights.


Affected software

Linux kernel

How to mitigate CVE-2026-93282

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3

External References

Related Security Bulletins