CVE-2026-93191
N/A
Summary
In the Linux kernel, the following vulnerability has been resolved:
smack: fix incorrect task context in smack_msg_queue_msgrcv
The smack_msg_queue_msgrcv() function incorrectly checks the permissions of the 'current' task instead of the 'target' task.
In the msgsnd() syscall path, if a receiver is already waiting, the pipelined_send() optimization is used to push the message directly to the receiver task:
ipc/msg.c`pipelined_send():
` smp_store_release(&msr->r_msg, msg)
In this case, the 'sender' (current) task performs the check on behalf of the 'receiver' task (msr->r_tsk, passed as the 'target' parameter):
ipc/msg.cpipelined_send(): security_msg_queue_msgrcv(,, target := msr->r_tsk,,)
However, smack_msg_queue_msgrcv() ignores the 'target' and checks 'current':
smack_msg_queue_msgrcv(…) ` smk_curacc_msq(isp, MAY_READWRITE); // current task
'current' MAY satisfy smack_msg_queue_msgrcv r/w requirement, but 'target' (the receiver task) might NOT; as a result, an unauthorized receiver gets the message, violating MAC policy.
Test:
- create a sysv message queue with label “foo”
- echo "bar foo r" >/smack/load2
- msgrcv(,,,0,MSG_NOERROR) in "bar"-labeled task. The task is waiting for the messages …
- msgsnd() from a "foo"-labeled task: "bar"-labeled task gets the message.
This patch fixes the issue by checking permission on the 'target' task instead of 'current'.
(2008-02-04, Casey Schaufler)
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | e114e473771c848c3cfec05f0123e70f1cdbdc99 < 4e49f997ef0c569e09b42aab6bd38c7c54ea095d | affected |
| Linux | Linux | e114e473771c848c3cfec05f0123e70f1cdbdc99 < dbece6c2f80b0470d8d99d7a016827dce99ed6e3 | affected |
| Linux | Linux | e114e473771c848c3cfec05f0123e70f1cdbdc99 < 7be4bd21c50afa83c93799b0f16cf5bfa493194e | affected |
| Linux | Linux | e114e473771c848c3cfec05f0123e70f1cdbdc99 < ec47f4177046dfaaf1cebb15f4d2e7b543475daf | affected |
| Linux | Linux | e114e473771c848c3cfec05f0123e70f1cdbdc99 < e35dc5a4ed6d1e536382d80c685187511ff248a1 | affected |
| Linux | Linux | e114e473771c848c3cfec05f0123e70f1cdbdc99 < c2ab27c2e11591524b1378c24ad18882a425d1fa | affected |
| Linux | Linux | e114e473771c848c3cfec05f0123e70f1cdbdc99 < d02c55e3ea82e41ea2c2026e08201e5daa4d0cfe | affected |
| Linux | Linux | e114e473771c848c3cfec05f0123e70f1cdbdc99 < fba3d32825f4bbc8e20f0cdc3b14df57965b8fe5 | affected |
| Linux | Linux | 2.6.25 | affected |
| Linux | Linux | 0 < 2.6.25 | unaffected |
| Linux | Linux | 5.10.270 <= 5.10.* | unaffected |
| Linux | Linux | 5.15.221 <= 5.15.* | unaffected |
| Linux | Linux | 6.1.188 <= 6.1.* | unaffected |
| Linux | Linux | 6.6.157 <= 6.6.* | unaffected |
| Linux | Linux | 6.12.110 <= 6.12.* | unaffected |
| Linux | Linux | 6.18.52 <= 6.18.* | unaffected |
| Linux | Linux | 7.2.6 <= 7.2.* | unaffected |
| Linux | Linux | 7.3-rc1 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/4e49f997ef0c569e09b42aab6bd38c7c54ea095d
- https://git.kernel.org/stable/c/dbece6c2f80b0470d8d99d7a016827dce99ed6e3
- https://git.kernel.org/stable/c/7be4bd21c50afa83c93799b0f16cf5bfa493194e
- https://git.kernel.org/stable/c/ec47f4177046dfaaf1cebb15f4d2e7b543475daf
- https://git.kernel.org/stable/c/e35dc5a4ed6d1e536382d80c685187511ff248a1
- https://git.kernel.org/stable/c/c2ab27c2e11591524b1378c24ad18882a425d1fa
- https://git.kernel.org/stable/c/d02c55e3ea82e41ea2c2026e08201e5daa4d0cfe
- https://git.kernel.org/stable/c/fba3d32825f4bbc8e20f0cdc3b14df57965b8fe5
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.