Description
In the Linux kernel, the following vulnerability has been resolved:

smb: client: clear setuid/setgid bit on write with cifsacl/modefromsid/posix extensions

When a file has the setuid or setgid bit set and is written to, the VFS
strips those bits and issues a setattr with ATTR_KILL_SUID/ATTR_KILL_SGID
together with an ATTR_MODE carrying the already-cleared mode.

Both cifs_setattr_unix() and cifs_setattr_nounix() unconditionally dropped
ATTR_MODE in that case:

/* skip mode change if it's just for clearing setuid/setgid */
if (attrs->ia_valid & (ATTR_KILL_SUID|ATTR_KILL_SGID))
attrs->ia_valid &= ~ATTR_MODE;

This is fine for the default mount, where the mode is only emulated via
the DOS read-only attribute and cannot represent the setuid/setgid bits
anyway. However, with the "cifsacl" or "modefromsid" mount options the
mode is stored on the server through an ACL (id_mode_to_cifs_acl()), with
the SMB3.1.1 POSIX extensions the mode is sent to the server directly,
and with the SMB1 Unix extensions (cifs_setattr_unix) the mode is sent
via CIFSSMBUnixSetPathInfo(). In all those cases dropping ATTR_MODE means
the cleared mode is never pushed to the server, so the setuid/setgid bit
survives the write.

This is a security issue: on local filesystems the setuid bit is stripped
when a file is written, but over these cifs.ko mounts the bit persists on
the server, potentially allowing an unexpected privilege escalation on
subsequent execution.

Fix this in two places:

1. cifs_setattr_nounix(): only take the "skip mode change" shortcut
when the mode is emulated via the DOS read-only attribute (i.e.
neither cifsacl/modefromsid nor the SMB3.1.1 POSIX extensions are
in effect), so that the cleared mode is propagated to the server
in the ACL / POSIX cases.

2. cifs_setattr_unix(): this function is only called when Unix
extensions are in effect, so the mode is always stored on the
server. Remove the shortcut entirely so that the cleared mode is
always pushed.
Published: 2026-09-11
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege escalation via persistent setuid/setgid bits on CIFS mounts
Action: Patch Immediately
AI Analysis

Impact

The vulnerability resides in the Linux a file with setuid or setgid bits set causes the kernel to strip those bits locally but fails to propagate the cleared mode back to the server when the CIFS share is mounted with cifsacl, modefromsid, or SMB 3.1.1 POSIX extensions. Based on the description, this flaw permits the setuid/setgid bits to persist on the server after a write, enabling a privilege‑escalation path when the file is later executed by a higher‑privileged user. The issue is categorized as CWE-281, an improper permission assignment vulnerability.

Affected Systems

The affected systems are Linux servers or workstations running any kernel that includes the CIFS client and mounts Windows shares using the cifsacl or modefromsid options, or that are configured to use the SMB 3.1.1 POSIX extensions. All kernel versions before the recent patch that addressed this bug are vulnerable, regardless of distribution or kernel release level, because the flaw originates in the core kernel source code for the CIFS file system.

Risk and Exploitability

The CVSS score of 7.8 places this flaw in the high severity range, while the EPSS score of less than 1 percent indicates a very low probability of active exploitation. The likely attack vector is that an attacker must have write access to the affected CIFS share and the ability to‑privileged user; thus the exposure is limited to users with network share permissions. Since it is not listed in the CISA KEV catalog, no known public exploits are required to assess the risk.

Generated by OpenCVE AI on September 15, 2026 at 21:03 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a patched release that includes the CIFS client fix.
  • Remount CIFS shares using options that avoid cifsacl, modefromsid, or SMB 3.1.1 POSIX extensions, ensuring setuid and setgid bits are cleared on the server.
  • Restrict write permissions on CIFS shares and remove setuid and setgid bits from files when not needed.

Generated by OpenCVE AI on September 15, 2026 at 21:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:N'}

cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-281
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:N'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: smb: client: clear setuid/setgid bit on write with cifsacl/modefromsid/posix extensions When a file has the setuid or setgid bit set and is written to, the VFS strips those bits and issues a setattr with ATTR_KILL_SUID/ATTR_KILL_SGID together with an ATTR_MODE carrying the already-cleared mode. Both cifs_setattr_unix() and cifs_setattr_nounix() unconditionally dropped ATTR_MODE in that case: /* skip mode change if it's just for clearing setuid/setgid */ if (attrs->ia_valid & (ATTR_KILL_SUID|ATTR_KILL_SGID)) attrs->ia_valid &= ~ATTR_MODE; This is fine for the default mount, where the mode is only emulated via the DOS read-only attribute and cannot represent the setuid/setgid bits anyway. However, with the "cifsacl" or "modefromsid" mount options the mode is stored on the server through an ACL (id_mode_to_cifs_acl()), with the SMB3.1.1 POSIX extensions the mode is sent to the server directly, and with the SMB1 Unix extensions (cifs_setattr_unix) the mode is sent via CIFSSMBUnixSetPathInfo(). In all those cases dropping ATTR_MODE means the cleared mode is never pushed to the server, so the setuid/setgid bit survives the write. This is a security issue: on local filesystems the setuid bit is stripped when a file is written, but over these cifs.ko mounts the bit persists on the server, potentially allowing an unexpected privilege escalation on subsequent execution. Fix this in two places: 1. cifs_setattr_nounix(): only take the "skip mode change" shortcut when the mode is emulated via the DOS read-only attribute (i.e. neither cifsacl/modefromsid nor the SMB3.1.1 POSIX extensions are in effect), so that the cleared mode is propagated to the server in the ACL / POSIX cases. 2. cifs_setattr_unix(): this function is only called when Unix extensions are in effect, so the mode is always stored on the server. Remove the shortcut entirely so that the cleared mode is always pushed.
Title smb: client: clear setuid/setgid bit on write with cifsacl/modefromsid/posix extensions
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-13T06:32:18.174Z

Reserved: 2026-09-11T19:38:34.740Z

Link: CVE-2026-89638

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:49.493

Modified: 2026-09-13T07:17:29.003

Link: CVE-2026-89638

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:45:31Z

Links: CVE-2026-89638 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T21:15:14Z

Weaknesses
  • CWE-281

    Improper Preservation of Permissions