Description
In the Linux kernel, the following vulnerability has been resolved:

smack: fix incorrect task context in smack_msg_queue_msgrcv

The smack_msg_queue_msgrcv() function incorrectly checks
the permissions of the 'current' task instead of the
'target' task.

In the msgsnd() syscall path, if a receiver is already waiting,
the pipelined_send() optimization is used to push the message
directly to the receiver task:

ipc/msg.c`pipelined_send():
` smp_store_release(&msr->r_msg, msg)

In this case, the 'sender' (current) task performs the check
on behalf of the 'receiver' task (msr->r_tsk, passed as the
'target' parameter):

ipc/msg.c`pipelined_send():
` security_msg_queue_msgrcv(,, target := msr->r_tsk,,)

However, smack_msg_queue_msgrcv() ignores the 'target' and
checks 'current':

smack_msg_queue_msgrcv(…)
` smk_curacc_msq(isp, MAY_READWRITE); // current task

'current' MAY satisfy smack_msg_queue_msgrcv r/w requirement,
but 'target' (the receiver task) might NOT;
as a result, an unauthorized receiver gets the message,
violating MAC policy.

Test:
1) create a sysv message queue with label “foo”
2) echo "bar foo r" >/smack/load2
3) msgrcv(,,,0,MSG_NOERROR) in "bar"-labeled task.
The task is waiting for the messages ...
4) msgsnd() from a "foo"-labeled task:
"bar"-labeled task gets the message.

This patch fixes the issue by checking permission on the
'target' task instead of 'current'.

(2008-02-04, Casey Schaufler)
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Receipt of System Messages and Potential Privilege Escalation
Action: Apply Patch
AI Analysis

Impact

In the Linux kernel, a flaw in the SMACK security module caused the function that receives messages from a System V message queue to check the permissions of the sending process instead of the intended receiver. This incorrect task context means that a sender with privileges to send messages can bypass the mandatory access control policy and deliver messages to a receiver that should have been denied. The result is that an unauthorized process can read data it is not meant to see, potentially exposing sensitive information or disrupting normal operation, which is an instance of improper access control (CWE‑284).

Affected Systems

This vulnerability is present in all releases of the Linux kernel that implement SMACK, regardless of the distribution, because the CPE string is cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* and no specific version range is supplied. The user should verify whether their kernel compilation includes SMACK support and whether any custom patches have applied the fix described in the advisory. If the system is using a custom kernel or a downstream distribution kernel without the SMACK update, it is likely affected.

Risk and Exploitability

The vulnerability allows a privileged sender to bypass SMACK enforcement and deliver a message to an unauthorized receiver via System V message queues. While the EPSS score is < 1%, indicating low overall exploitation likelihood, the potential impact is significant: an attacker can read or influence data protected by the MAC policy in a privileged process. The KEV status shows that this vulnerability is not currently listed as a known exploited vulnerability. Available evidence indicates the flaw is exploitable when the kernel is compiled with SMACK enabled and System V message queues are used; the attack does not require network access and can occur entirely locally within the host.

Generated by OpenCVE AI on September 19, 2026 at 09:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that includes the SMACK fix for smack_msg_queue_msgrcv.
  • If a kernel upgrade is not immediately possible, disable SMACK enforcement for the affected processes or restrict the use of System V message queues.
  • If you maintain custom kernel builds, apply the SMACK patch from the kernel source upstream.

Generated by OpenCVE AI on September 19, 2026 at 09:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 09:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: smack: fix incorrect task context in smack_msg_queue_msgrcv The smack_msg_queue_msgrcv() function incorrectly checks the permissions of the 'current' task instead of the 'target' task. In the msgsnd() syscall path, if a receiver is already waiting, the pipelined_send() optimization is used to push the message directly to the receiver task: ipc/msg.c`pipelined_send(): ` smp_store_release(&msr->r_msg, msg) In this case, the 'sender' (current) task performs the check on behalf of the 'receiver' task (msr->r_tsk, passed as the 'target' parameter): ipc/msg.c`pipelined_send(): ` security_msg_queue_msgrcv(,, target := msr->r_tsk,,) However, smack_msg_queue_msgrcv() ignores the 'target' and checks 'current': smack_msg_queue_msgrcv(…) ` smk_curacc_msq(isp, MAY_READWRITE); // current task 'current' MAY satisfy smack_msg_queue_msgrcv r/w requirement, but 'target' (the receiver task) might NOT; as a result, an unauthorized receiver gets the message, violating MAC policy. Test: 1) create a sysv message queue with label “foo” 2) echo "bar foo r" >/smack/load2 3) msgrcv(,,,0,MSG_NOERROR) in "bar"-labeled task. The task is waiting for the messages ... 4) msgsnd() from a "foo"-labeled task: "bar"-labeled task gets the message. This patch fixes the issue by checking permission on the 'target' task instead of 'current'. (2008-02-04, Casey Schaufler)
Title smack: fix incorrect task context in smack_msg_queue_msgrcv
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:12:15.765Z

Reserved: 2026-09-17T16:02:15.092Z

Link: CVE-2026-93191

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:18:15.307

Modified: 2026-09-17T17:18:15.307

Link: CVE-2026-93191

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T06:00:13Z

Weaknesses