CVE-2026-52944

medium

Description

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix FSCTL permission bypass by adding a permission check for FSCTL_SET_SPARSE FSCTL_SET_SPARSE in fsctl_set_sparse() modifies the file's sparse attribute and saves it through xattr without any permission checks. This exposes two issues: 1) A client on a read-only share can change the sparse attribute on files it opened, even though the share is read-only. Other FSCTL write operations already check test_tree_conn_flag(work->tcon, KSMBD_TREE_CONN_FLAG_WRITABLE), but FSCTL_SET_SPARSE does not. 2) Even on writable shares, clients without FILE_WRITE_DATA or FILE_WRITE_ATTRIBUTES access should not modify the sparse attribute. Similar handle-level checks exist in other functions but are missing here. Add both share-level writable check and per-handle access check. Use goto out on error to avoid leaking file references.

References

https://git.kernel.org/stable/c/ef664475c1bf1a27d45dae6848ca9c9c4d86853f

https://git.kernel.org/stable/c/de9eb0b44fa9123170e6245b49638e0e453c10f8

https://git.kernel.org/stable/c/cc57232cae23c0df91b4a59d0f519141ce9b5b02

https://git.kernel.org/stable/c/c5ab11263e3c89aa7989afc5374ef7743e092fd0

https://git.kernel.org/stable/c/aef151bcfa494bfe983669de2726734b534adb73

https://git.kernel.org/stable/c/3a9a0a1c38ef90788f5d7c4b29903c8b220f744a

https://git.kernel.org/stable/c/3127a884525dc8ca4def73254bfcd3ccef0bf812

Details

Source: Mitre, NVD

Published: 2026-06-24

Updated: 2026-09-14

Risk Information

CVSS v2

Base Score: 4.6

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

Severity: Medium

CVSS v3

Base Score: 5.5

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Severity: Medium

EPSS

EPSS: 0.00219