« Volver al listado

CVE-2026-93191

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

smack: fix incorrect task context in smack_msg_queue_msgrcv

The smack_msg_queue_msgrcv() function incorrectly checks the permissions of the 'current' task instead of the 'target' task.

In the msgsnd() syscall path, if a receiver is already waiting, the pipelined_send() optimization is used to push the message directly to the receiver task:

In this case, the 'sender' (current) task performs the check on behalf of the 'receiver' task (msr->r_tsk, passed as the 'target' parameter):

However, smack_msg_queue_msgrcv() ignores the 'target' and checks 'current':

Leer descripción completaMostrar menos

'current' MAY satisfy smack_msg_queue_msgrcv r/w requirement, but 'target' (the receiver task) might NOT; as a result, an unauthorized receiver gets the message, violating MAC policy.

Test: 1) create a sysv message queue with label “foo” 2) echo "bar foo r" >/smack/load2 3) msgrcv(,,,0,MSG_NOERROR) in "bar"-labeled task. The task is waiting for the messages ... 4) msgsnd() from a "foo"-labeled task: "bar"-labeled task gets the message.

This patch fixes the issue by checking permission on the 'target' task instead of 'current'.

(2008-02-04, Casey Schaufler)

Detalles técnicos trazas, registros y código del informe original
    ipc/msg.c`pipelined_send():
    ` smp_store_release(&msr->r_msg, msg)

  ipc/msg.c`pipelined_send():
  ` security_msg_queue_msgrcv(,, target := msr->r_tsk,,)

  smack_msg_queue_msgrcv(…)
  ` smk_curacc_msq(isp, MAY_READWRITE); // current task

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-93191",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "e114e473771c848c3cfec05f0123e70f1cdbdc99",
              "lessThan": "4e49f997ef0c569e09b42aab6bd38c7c54ea095d",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "e114e473771c848c3cfec05f0123e70f1cdbdc99",
              "lessThan": "dbece6c2f80b0470d8d99d7a016827dce99ed6e3",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "e114e473771c848c3cfec05f0123e70f1cdbdc99",
              "lessThan": "7be4bd21c50afa83c93799b0f16cf5bfa493194e",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "e114e473771c848c3cfec05f0123e70f1cdbdc99",
              "lessThan": "ec47f4177046dfaaf1cebb15f4d2e7b543475daf",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "e114e473771c848c3cfec05f0123e70f1cdbdc99",
              "lessThan": "e35dc5a4ed6d1e536382d80c685187511ff248a1",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "e114e473771c848c3cfec05f0123e70f1cdbdc99",
              "lessThan": "c2ab27c2e11591524b1378c24ad18882a425d1fa",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "e114e473771c848c3cfec05f0123e70f1cdbdc99",
              "lessThan": "d02c55e3ea82e41ea2c2026e08201e5daa4d0cfe",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "e114e473771c848c3cfec05f0123e70f1cdbdc99",
              "lessThan": "fba3d32825f4bbc8e20f0cdc3b14df57965b8fe5",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "security/smack/smack_lsm.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "2.6.25"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "2.6.25",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.270",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.221",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.188",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.157",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.110",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.52",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.6",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "security/smack/smack_lsm.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-17T17:18:15.307",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/4e49f997ef0c569e09b42aab6bd38c7c54ea095d",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/7be4bd21c50afa83c93799b0f16cf5bfa493194e",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/c2ab27c2e11591524b1378c24ad18882a425d1fa",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/d02c55e3ea82e41ea2c2026e08201e5daa4d0cfe",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/dbece6c2f80b0470d8d99d7a016827dce99ed6e3",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/e35dc5a4ed6d1e536382d80c685187511ff248a1",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/ec47f4177046dfaaf1cebb15f4d2e7b543475daf",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/fba3d32825f4bbc8e20f0cdc3b14df57965b8fe5",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmack: fix incorrect task context in smack_msg_queue_msgrcv\n\nThe smack_msg_queue_msgrcv() function incorrectly checks\nthe permissions of the 'current' task instead of the\n'target' task.\n\nIn the msgsnd() syscall path, if a receiver is already waiting,\nthe pipelined_send() optimization is used to push the message\ndirectly to the receiver task:\n\n    ipc/msg.c`pipelined_send():\n    ` smp_store_release(&msr->r_msg, msg)\n\nIn this case, the 'sender' (current) task performs the check\non behalf of the 'receiver' task (msr->r_tsk, passed as the\n'target' parameter):\n\n  ipc/msg.c`pipelined_send():\n  ` security_msg_queue_msgrcv(,, target := msr->r_tsk,,)\n\nHowever, smack_msg_queue_msgrcv() ignores the 'target' and\nchecks 'current':\n\n  smack_msg_queue_msgrcv(…)\n  ` smk_curacc_msq(isp, MAY_READWRITE); // current task\n\n'current' MAY satisfy smack_msg_queue_msgrcv r/w requirement,\nbut 'target' (the receiver task) might NOT;\nas a result, an unauthorized receiver gets the message,\nviolating MAC policy.\n\nTest:\n1) create a sysv message queue with label “foo”\n2) echo \"bar foo r\" >/smack/load2\n3) msgrcv(,,,0,MSG_NOERROR) in \"bar\"-labeled task.\n    The task is waiting for the messages ...\n4) msgsnd() from a \"foo\"-labeled task:\n\"bar\"-labeled task gets the message.\n\nThis patch fixes the issue by checking permission on the\n'target' task instead of 'current'.\n\n(2008-02-04, Casey Schaufler)"
    }
  ],
  "lastModified": "2026-09-17T17:18:15.307",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}