CyberRota Analysis
AI-GeneratedA vulnerability in the Linux kernel affects the ksmbd module, which improperly handles the inheritance of POSIX ACL masks during the creation of child objects. This flaw can lead to unintended widening of effective permissions, potentially allowing unauthorized access to SMB objects. Organizations utilizing Linux systems with SMB services should prioritize addressing this issue to maintain proper access controls and prevent potential security breaches.
Original NVD Description
In the Linux kernel, the following vulnerability has been resolved: ksmbd: preserve VFS inherited POSIX ACL mask The VFS initializes a child's POSIX ACL from the parent's default ACL and the requested creation mode. Do not mutate the parent ACL or overwrite the child's VFS-computed access and default ACLs afterwards. This preserves restrictive ACL_MASK entries and prevents SMB object creation from widening effective permissions.