CVE-2026-93282
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: fix maximum allowed access checks
The DACL permission check looks for an ACE matching the current user and falls back to the Everyone ACE. It does not consider an Authenticated Users ACE, even though an authenticated session is a member of that well-known group.
As a result, opening a file whose access is granted through S-1-5-11 can incorrectly fail with STATUS_ACCESS_DENIED. Treat an Authenticated Users ACE as a fallback entry alongside Everyone.
The maximal access calculation also combines access masks from every ACE, regardless of whether its SID applies to the current user. This can grant rights belonging to an unrelated principal.
Leer descripción completaMostrar menos
Process only ACEs applying to the user, Everyone, or Authenticated Users, and accumulate allowed and denied masks in ACL order. Preserve explicitly requested access bits so they are validated against the resulting maximal mask.
When ACCESS_SYSTEM_SECURITY is denied, report STATUS_PRIVILEGE_NOT_HELD instead of the generic STATUS_ACCESS_DENIED. Access to the system ACL requires a security privilege that ksmbd does not grant.
For regular files, include FILE_EXECUTE in maximal access when the client requested GENERIC_EXECUTE and the DACL grants the complete file-read set. Keep a direct FILE_EXECUTE request subject to the explicit DACL bit. This matches the POSIX file ACL mapping without broadening specific execute requests.
Do not replace rights from an applicable NT ACE with a POSIX ACL entry. The POSIX ACL is only a fallback when no user, Everyone, or Authenticated Users ACE applies; otherwise it can incorrectly broaden the stored DACL.
This fixes smb2.maximum_allowed.maximum_allowed.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
- Puntuación base: 8.1
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.31%
- Percentil entre todas las CVEs puntuadas: 21
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1210Exploitation of Remote Serviceslateral movement65 % - Impacto principal
T1078.001Default Accountsstealth · persistence · privilege escalation · initial access75 % - Impacto secundario
T1552.001Credentials In Filescredential access60 %
Vulnerabilidad en ksmbd (SMB kernel) que permite escalada de privilegios de acceso mediante fallos en validación de ACL y grupos autenticados remotamente. AV:N con PR:L permite acceso no autorizado a archivos (C:H, I:H).
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-93282",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Secondary",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8.1,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.2,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9",
"lessThan": "35d5c59fe6b1d9fe43fb14eb384f69ee1a120f9c",
"versionType": "git"
},
{
"status": "affected",
"version": "e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9",
"lessThan": "cc2f133e80eb2c4a04bfa77a2f207749fe2f516a",
"versionType": "git"
}
],
"programFiles": [
"fs/smb/server/smb2pdu.c",
"fs/smb/server/smbacl.c",
"fs/smb/server/smbacl.h"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "5.15"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "5.15",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "7.2.6",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"fs/smb/server/smb2pdu.c",
"fs/smb/server/smbacl.c",
"fs/smb/server/smbacl.h"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-24T16:17:25.570",
"references": [
{
"url": "https://git.kernel.org/stable/c/35d5c59fe6b1d9fe43fb14eb384f69ee1a120f9c",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/cc2f133e80eb2c4a04bfa77a2f207749fe2f516a",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: fix maximum allowed access checks\n\nThe DACL permission check looks for an ACE matching the current user and\nfalls back to the Everyone ACE. It does not consider an Authenticated\nUsers ACE, even though an authenticated session is a member of that\nwell-known group.\n\nAs a result, opening a file whose access is granted through S-1-5-11 can\nincorrectly fail with STATUS_ACCESS_DENIED. Treat an Authenticated Users\nACE as a fallback entry alongside Everyone.\n\nThe maximal access calculation also combines access masks from every ACE,\nregardless of whether its SID applies to the current user. This can grant\nrights belonging to an unrelated principal. Process only ACEs applying to\nthe user, Everyone, or Authenticated Users, and accumulate allowed and\ndenied masks in ACL order. Preserve explicitly requested access bits so\nthey are validated against the resulting maximal mask.\n\nWhen ACCESS_SYSTEM_SECURITY is denied, report STATUS_PRIVILEGE_NOT_HELD\ninstead of the generic STATUS_ACCESS_DENIED. Access to the system ACL\nrequires a security privilege that ksmbd does not grant.\n\nFor regular files, include FILE_EXECUTE in maximal access when the client\nrequested GENERIC_EXECUTE and the DACL grants the complete file-read set.\nKeep a direct FILE_EXECUTE request subject to the explicit DACL bit. This\nmatches the POSIX file ACL mapping without broadening specific execute\nrequests.\n\nDo not replace rights from an applicable NT ACE with a POSIX ACL entry.\nThe POSIX ACL is only a fallback when no user, Everyone, or Authenticated\nUsers ACE applies; otherwise it can incorrectly broaden the stored DACL.\n\nThis fixes smb2.maximum_allowed.maximum_allowed."
}
],
"lastModified": "2026-09-25T13:17:18.310",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}