-
CVE-2026-93191
- EPSS 0.2%
- Veröffentlicht 17.09.2026 16:12:15
- Zuletzt bearbeitet 17.09.2026 17:18:15
- Erkennungen
smack: fix incorrect task context in smack_msg_queue_msgrcv
In the Linux kernel, the following vulnerability has been resolved:
smack: fix incorrect task context in smack_msg_queue_msgrcv
The smack_msg_queue_msgrcv() function incorrectly checks
the permissions of the 'current' task instead of the
'target' task.
In the msgsnd() syscall path, if a receiver is already waiting,
the pipelined_send() optimization is used to push the message
directly to the receiver task:
ipc/msg.c`pipelined_send():
` smp_store_release(&msr->r_msg, msg)
In this case, the 'sender' (current) task performs the check
on behalf of the 'receiver' task (msr->r_tsk, passed as the
'target' parameter):
ipc/msg.c`pipelined_send():
` security_msg_queue_msgrcv(,, target := msr->r_tsk,,)
However, smack_msg_queue_msgrcv() ignores the 'target' and
checks 'current':
smack_msg_queue_msgrcv(…)
` smk_curacc_msq(isp, MAY_READWRITE); // current task
'current' MAY satisfy smack_msg_queue_msgrcv r/w requirement,
but 'target' (the receiver task) might NOT;
as a result, an unauthorized receiver gets the message,
violating MAC policy.
Test:
1) create a sysv message queue with label “foo”
2) echo "bar foo r" >/smack/load2
3) msgrcv(,,,0,MSG_NOERROR) in "bar"-labeled task.
The task is waiting for the messages ...
4) msgsnd() from a "foo"-labeled task:
"bar"-labeled task gets the message.
This patch fixes the issue by checking permission on the
'target' task instead of 'current'.
(2008-02-04, Casey Schaufler)Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
e114e473771c848c3cfec05f0123e70f1cdbdc99
Version <
4e49f997ef0c569e09b42aab6bd38c7c54ea095d
Status
affected
Version
e114e473771c848c3cfec05f0123e70f1cdbdc99
Version <
dbece6c2f80b0470d8d99d7a016827dce99ed6e3
Status
affected
Version
e114e473771c848c3cfec05f0123e70f1cdbdc99
Version <
7be4bd21c50afa83c93799b0f16cf5bfa493194e
Status
affected
Version
e114e473771c848c3cfec05f0123e70f1cdbdc99
Version <
ec47f4177046dfaaf1cebb15f4d2e7b543475daf
Status
affected
Version
e114e473771c848c3cfec05f0123e70f1cdbdc99
Version <
e35dc5a4ed6d1e536382d80c685187511ff248a1
Status
affected
Version
e114e473771c848c3cfec05f0123e70f1cdbdc99
Version <
c2ab27c2e11591524b1378c24ad18882a425d1fa
Status
affected
Version
e114e473771c848c3cfec05f0123e70f1cdbdc99
Version <
d02c55e3ea82e41ea2c2026e08201e5daa4d0cfe
Status
affected
Version
e114e473771c848c3cfec05f0123e70f1cdbdc99
Version <
fba3d32825f4bbc8e20f0cdc3b14df57965b8fe5
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
2.6.25
Status
affected
Version
0
Version <
2.6.25
Status
unaffected
Version <=
5.10.*
Version
5.10.270
Status
unaffected
Version <=
5.15.*
Version
5.15.221
Status
unaffected
Version <=
6.1.*
Version
6.1.188
Status
unaffected
Version <=
6.6.*
Version
6.6.157
Status
unaffected
Version <=
6.12.*
Version
6.12.110
Status
unaffected
Version <=
6.18.*
Version
6.18.52
Status
unaffected
Version <=
7.2.*
Version
7.2.6
Status
unaffected
Version <=
*
Version
7.3-rc1
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.2% | 0.097 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|
https://git.kernel.org/stable/c/4e49f997ef0c569e09b42aab6bd38c7c54ea095d
https://git.kernel.org/stable/c/dbece6c2f80b0470d8d99d7a016827dce99ed6e3
https://git.kernel.org/stable/c/7be4bd21c50afa83c93799b0f16cf5bfa493194e
https://git.kernel.org/stable/c/ec47f4177046dfaaf1cebb15f4d2e7b543475daf
https://git.kernel.org/stable/c/e35dc5a4ed6d1e536382d80c685187511ff248a1
https://git.kernel.org/stable/c/c2ab27c2e11591524b1378c24ad18882a425d1fa
https://git.kernel.org/stable/c/d02c55e3ea82e41ea2c2026e08201e5daa4d0cfe
https://git.kernel.org/stable/c/fba3d32825f4bbc8e20f0cdc3b14df57965b8fe5