CVE-2026-93191

Summary

In the Linux kernel, the following vulnerability has been resolved:

smack: fix incorrect task context in smack_msg_queue_msgrcv

The smack_msg_queue_msgrcv() function incorrectly checks the permissions of the 'current' task instead of the 'target' task.

In the msgsnd() syscall path, if a receiver is already waiting, the pipelined_send() optimization is used to push the message directly to the receiver task:

ipc/msg.c`pipelined_send():
` smp_store_release(&msr->r_msg, msg)

In this case, the 'sender' (current) task performs the check on behalf of the 'receiver' task (msr->r_tsk, passed as the 'target' parameter):

ipc/msg.cpipelined_send(): security_msg_queue_msgrcv(,, target := msr->r_tsk,,)

However, smack_msg_queue_msgrcv() ignores the 'target' and checks 'current':

smack_msg_queue_msgrcv(…) ` smk_curacc_msq(isp, MAY_READWRITE); // current task

'current' MAY satisfy smack_msg_queue_msgrcv r/w requirement, but 'target' (the receiver task) might NOT; as a result, an unauthorized receiver gets the message, violating MAC policy.

Test:

  1. create a sysv message queue with label “foo”
  2. echo "bar foo r" >/smack/load2
  3. msgrcv(,,,0,MSG_NOERROR) in "bar"-labeled task. The task is waiting for the messages …
  4. msgsnd() from a "foo"-labeled task: "bar"-labeled task gets the message.

This patch fixes the issue by checking permission on the 'target' task instead of 'current'.

(2008-02-04, Casey Schaufler)

Affected Software

VendorProductVersion RangeStatus
LinuxLinuxe114e473771c848c3cfec05f0123e70f1cdbdc99 < 4e49f997ef0c569e09b42aab6bd38c7c54ea095daffected
LinuxLinuxe114e473771c848c3cfec05f0123e70f1cdbdc99 < dbece6c2f80b0470d8d99d7a016827dce99ed6e3affected
LinuxLinuxe114e473771c848c3cfec05f0123e70f1cdbdc99 < 7be4bd21c50afa83c93799b0f16cf5bfa493194eaffected
LinuxLinuxe114e473771c848c3cfec05f0123e70f1cdbdc99 < ec47f4177046dfaaf1cebb15f4d2e7b543475dafaffected
LinuxLinuxe114e473771c848c3cfec05f0123e70f1cdbdc99 < e35dc5a4ed6d1e536382d80c685187511ff248a1affected
LinuxLinuxe114e473771c848c3cfec05f0123e70f1cdbdc99 < c2ab27c2e11591524b1378c24ad18882a425d1faaffected
LinuxLinuxe114e473771c848c3cfec05f0123e70f1cdbdc99 < d02c55e3ea82e41ea2c2026e08201e5daa4d0cfeaffected
LinuxLinuxe114e473771c848c3cfec05f0123e70f1cdbdc99 < fba3d32825f4bbc8e20f0cdc3b14df57965b8fe5affected
LinuxLinux2.6.25affected
LinuxLinux0 < 2.6.25unaffected
LinuxLinux5.10.270 <= 5.10.*unaffected
LinuxLinux5.15.221 <= 5.15.*unaffected
LinuxLinux6.1.188 <= 6.1.*unaffected
LinuxLinux6.6.157 <= 6.6.*unaffected
LinuxLinux6.12.110 <= 6.12.*unaffected
LinuxLinux6.18.52 <= 6.18.*unaffected
LinuxLinux7.2.6 <= 7.2.*unaffected
LinuxLinux7.3-rc1 <= *unaffected

Weaknesses

References