Impact
The vulnerability resides in the Linux a file with setuid or setgid bits set causes the kernel to strip those bits locally but fails to propagate the cleared mode back to the server when the CIFS share is mounted with cifsacl, modefromsid, or SMB 3.1.1 POSIX extensions. Based on the description, this flaw permits the setuid/setgid bits to persist on the server after a write, enabling a privilege‑escalation path when the file is later executed by a higher‑privileged user. The issue is categorized as CWE-281, an improper permission assignment vulnerability.
Affected Systems
The affected systems are Linux servers or workstations running any kernel that includes the CIFS client and mounts Windows shares using the cifsacl or modefromsid options, or that are configured to use the SMB 3.1.1 POSIX extensions. All kernel versions before the recent patch that addressed this bug are vulnerable, regardless of distribution or kernel release level, because the flaw originates in the core kernel source code for the CIFS file system.
Risk and Exploitability
The CVSS score of 7.8 places this flaw in the high severity range, while the EPSS score of less than 1 percent indicates a very low probability of active exploitation. The likely attack vector is that an attacker must have write access to the affected CIFS share and the ability to‑privileged user; thus the exposure is limited to users with network share permissions. Since it is not listed in the CISA KEV catalog, no known public exploits are required to assess the risk.
OpenCVE Enrichment