CVE-2026-93191
In the Linux kernel, the following vulnerability has been resolved:
smack: fix incorrect task context in smack_msg_queue_msgrcv
The smack_msg_queue_msgrcv() function incorrectly checks the permissions of the 'current' task instead of the 'target' task.
In the msgsnd() syscall path, if a receiver is already waiting, the pipelined_send() optimization is used to push the message directly to the receiver task:
In this case, the 'sender' (current) task performs the check on behalf of the 'receiver' task (msr->r_tsk, passed as the 'target' parameter):
However, smack_msg_queue_msgrcv() ignores the 'target' and checks 'current':
Leer descripción completaMostrar menos
'current' MAY satisfy smack_msg_queue_msgrcv r/w requirement, but 'target' (the receiver task) might NOT; as a result, an unauthorized receiver gets the message, violating MAC policy.
Test: 1) create a sysv message queue with label “foo” 2) echo "bar foo r" >/smack/load2 3) msgrcv(,,,0,MSG_NOERROR) in "bar"-labeled task. The task is waiting for the messages ... 4) msgsnd() from a "foo"-labeled task: "bar"-labeled task gets the message.
This patch fixes the issue by checking permission on the 'target' task instead of 'current'.
(2008-02-04, Casey Schaufler)
Detalles técnicos trazas, registros y código del informe original
ipc/msg.c`pipelined_send():
` smp_store_release(&msr->r_msg, msg)
ipc/msg.c`pipelined_send():
` security_msg_queue_msgrcv(,, target := msr->r_tsk,,)
smack_msg_queue_msgrcv(…)
` smk_curacc_msq(isp, MAY_READWRITE); // current taskCVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.20%
- Percentil entre todas las CVEs puntuadas: 8
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/4e49f997ef0c569e09b42aab6bd38c7c54ea095d
- https://git.kernel.org/stable/c/7be4bd21c50afa83c93799b0f16cf5bfa493194e
- https://git.kernel.org/stable/c/c2ab27c2e11591524b1378c24ad18882a425d1fa
- https://git.kernel.org/stable/c/d02c55e3ea82e41ea2c2026e08201e5daa4d0cfe
- https://git.kernel.org/stable/c/dbece6c2f80b0470d8d99d7a016827dce99ed6e3
- https://git.kernel.org/stable/c/e35dc5a4ed6d1e536382d80c685187511ff248a1
- https://git.kernel.org/stable/c/ec47f4177046dfaaf1cebb15f4d2e7b543475daf
- https://git.kernel.org/stable/c/fba3d32825f4bbc8e20f0cdc3b14df57965b8fe5
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-93191",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "e114e473771c848c3cfec05f0123e70f1cdbdc99",
"lessThan": "4e49f997ef0c569e09b42aab6bd38c7c54ea095d",
"versionType": "git"
},
{
"status": "affected",
"version": "e114e473771c848c3cfec05f0123e70f1cdbdc99",
"lessThan": "dbece6c2f80b0470d8d99d7a016827dce99ed6e3",
"versionType": "git"
},
{
"status": "affected",
"version": "e114e473771c848c3cfec05f0123e70f1cdbdc99",
"lessThan": "7be4bd21c50afa83c93799b0f16cf5bfa493194e",
"versionType": "git"
},
{
"status": "affected",
"version": "e114e473771c848c3cfec05f0123e70f1cdbdc99",
"lessThan": "ec47f4177046dfaaf1cebb15f4d2e7b543475daf",
"versionType": "git"
},
{
"status": "affected",
"version": "e114e473771c848c3cfec05f0123e70f1cdbdc99",
"lessThan": "e35dc5a4ed6d1e536382d80c685187511ff248a1",
"versionType": "git"
},
{
"status": "affected",
"version": "e114e473771c848c3cfec05f0123e70f1cdbdc99",
"lessThan": "c2ab27c2e11591524b1378c24ad18882a425d1fa",
"versionType": "git"
},
{
"status": "affected",
"version": "e114e473771c848c3cfec05f0123e70f1cdbdc99",
"lessThan": "d02c55e3ea82e41ea2c2026e08201e5daa4d0cfe",
"versionType": "git"
},
{
"status": "affected",
"version": "e114e473771c848c3cfec05f0123e70f1cdbdc99",
"lessThan": "fba3d32825f4bbc8e20f0cdc3b14df57965b8fe5",
"versionType": "git"
}
],
"programFiles": [
"security/smack/smack_lsm.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.25"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "2.6.25",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "5.10.270",
"versionType": "semver",
"lessThanOrEqual": "5.10.*"
},
{
"status": "unaffected",
"version": "5.15.221",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.1.188",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.157",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.110",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.52",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2.6",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"security/smack/smack_lsm.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-17T17:18:15.307",
"references": [
{
"url": "https://git.kernel.org/stable/c/4e49f997ef0c569e09b42aab6bd38c7c54ea095d",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/7be4bd21c50afa83c93799b0f16cf5bfa493194e",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/c2ab27c2e11591524b1378c24ad18882a425d1fa",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/d02c55e3ea82e41ea2c2026e08201e5daa4d0cfe",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/dbece6c2f80b0470d8d99d7a016827dce99ed6e3",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/e35dc5a4ed6d1e536382d80c685187511ff248a1",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/ec47f4177046dfaaf1cebb15f4d2e7b543475daf",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/fba3d32825f4bbc8e20f0cdc3b14df57965b8fe5",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmack: fix incorrect task context in smack_msg_queue_msgrcv\n\nThe smack_msg_queue_msgrcv() function incorrectly checks\nthe permissions of the 'current' task instead of the\n'target' task.\n\nIn the msgsnd() syscall path, if a receiver is already waiting,\nthe pipelined_send() optimization is used to push the message\ndirectly to the receiver task:\n\n ipc/msg.c`pipelined_send():\n ` smp_store_release(&msr->r_msg, msg)\n\nIn this case, the 'sender' (current) task performs the check\non behalf of the 'receiver' task (msr->r_tsk, passed as the\n'target' parameter):\n\n ipc/msg.c`pipelined_send():\n ` security_msg_queue_msgrcv(,, target := msr->r_tsk,,)\n\nHowever, smack_msg_queue_msgrcv() ignores the 'target' and\nchecks 'current':\n\n smack_msg_queue_msgrcv(…)\n ` smk_curacc_msq(isp, MAY_READWRITE); // current task\n\n'current' MAY satisfy smack_msg_queue_msgrcv r/w requirement,\nbut 'target' (the receiver task) might NOT;\nas a result, an unauthorized receiver gets the message,\nviolating MAC policy.\n\nTest:\n1) create a sysv message queue with label “foo”\n2) echo \"bar foo r\" >/smack/load2\n3) msgrcv(,,,0,MSG_NOERROR) in \"bar\"-labeled task.\n The task is waiting for the messages ...\n4) msgsnd() from a \"foo\"-labeled task:\n\"bar\"-labeled task gets the message.\n\nThis patch fixes the issue by checking permission on the\n'target' task instead of 'current'.\n\n(2008-02-04, Casey Schaufler)"
}
],
"lastModified": "2026-09-17T17:18:15.307",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}