Impact
In the Linux kernel, a flaw in the SMACK security module caused the function that receives messages from a System V message queue to check the permissions of the sending process instead of the intended receiver. This incorrect task context means that a sender with privileges to send messages can bypass the mandatory access control policy and deliver messages to a receiver that should have been denied. The result is that an unauthorized process can read data it is not meant to see, potentially exposing sensitive information or disrupting normal operation, which is an instance of improper access control (CWE‑284).
Affected Systems
This vulnerability is present in all releases of the Linux kernel that implement SMACK, regardless of the distribution, because the CPE string is cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* and no specific version range is supplied. The user should verify whether their kernel compilation includes SMACK support and whether any custom patches have applied the fix described in the advisory. If the system is using a custom kernel or a downstream distribution kernel without the SMACK update, it is likely affected.
Risk and Exploitability
The vulnerability allows a privileged sender to bypass SMACK enforcement and deliver a message to an unauthorized receiver via System V message queues. While the EPSS score is < 1%, indicating low overall exploitation likelihood, the potential impact is significant: an attacker can read or influence data protected by the MAC policy in a privileged process. The KEV status shows that this vulnerability is not currently listed as a known exploited vulnerability. Available evidence indicates the flaw is exploitable when the kernel is compiled with SMACK enabled and System V message queues are used; the attack does not require network access and can occur entirely locally within the host.
OpenCVE Enrichment
Debian DLA
Debian DSA