CVE-2026-93786: ksmbd: preserve VFS inherited POSIX ACL mask

Published Sep 24, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

ksmbd: preserve VFS inherited POSIX ACL mask

The VFS initializes a child's POSIX ACL from the parent's default ACL and the requested creation mode. Do not mutate the parent ACL or overwrite the child's VFS-computed access and default ACLs afterwards.

This preserves restrictive ACLMASK entries and prevents SMB object creation from widening effective permissions.

Affected Software

1 affected component
Linux Linux kernel

Event History

Sep 24, 2026
CVE Published
via MITRE·04:02 PM
Data Sourced
via MITRE·04:02 PM
Description
Data Sourced
via NVD·05:17 PM
Description

Frequently Asked Questions

1

Which systems are exposed to this issue?

Systems using the Linux kernel's ksmbd SMB server are exposed when SMB clients can create objects in directories that use inherited POSIX default ACLs, particularly where restrictive ACL_MASK entries are expected to limit effective permissions.

2

What must an attacker be able to do to exploit it?

An attacker needs the ability to create SMB objects through ksmbd in a directory with a default POSIX ACL. The issue can cause created objects to receive broader effective permissions than the VFS-computed inherited ACL and requested creation mode should allow.

3

How can I determine whether this may have affected existing objects?

Review files and directories created through ksmbd beneath directories with default POSIX ACLs, and compare their effective ACL permissions and ACL_MASK entries with the parent directory's intended inherited restrictions. Objects whose permissions are wider than those restrictions may warrant remediation.

4

What can be done if the update cannot be applied immediately?

Limit untrusted users' ability to create objects through ksmbd in directories that rely on restrictive default POSIX ACLs. Review and correct ACLs on SMB-created objects, especially in locations where ACL_MASK restrictions are used.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203