OFFLINE
Awaiting data
Security intelligence
MajorCritical vulnerability

CVE-2026-93786 (CVSS 8.1)

NVD · officialPublished Sep 24, 2026Risk 37/100

In the Linux kernel, the following vulnerability has been resolved: ksmbd: preserve VFS inherited POSIX ACL mask The VFS initializes a child's POSIX ACL from the parent's default ACL and the requested creation mode. Do not mutate the parent ACL or overwrite the child's VFS-computed access and default ACLs afterwards. This preserves restrictive ACL_MASK entries and prevents SMB object creation from widening effective permissions.

CVSS
8.1
AV:NetworkAC:LowPR:LowUI:NoneC:HighI:HighA:None

This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source