{"id":"CVE-2026-89638","title":"kernel: smb: client: clear setuid/setgid bit on write with cifsacl/modefromsid/posix extensions (CVE-2026-89638)","summary":"A flaw was found in the Linux kernel's Server Message Block (SMB) client. When a file with the setuid or setgid bit is written to on certain Common Internet File System (CIFS) mounts (specifically those using 'cifsacl', 'modefromsid' optio…","severity":"high","cvss":7,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","cvssSource":"vendor","cwe":"CWE-281","vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","affected":["enterprise_linux 10","enterprise_linux 8","enterprise_linux 9","openshift_container_platform 4"],"published":"2026-09-11","updated":"2026-09-23","sourceUpdated":"2026-09-23T18:28:07+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89638.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89638.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-89638"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2532122"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-89638"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89638"},{"url":"https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-89638.mbox"},{"url":"https://git.kernel.org/stable/c/69bfe810ecd1e0387d8975d711cd326341d13c6e"},{"url":"https://git.kernel.org/stable/c/b10015807e4c628095d1d1d1c9307efc8cdd9e1b"},{"url":"https://git.kernel.org/stable/c/b8e5dc4f95e5484159b343903f302eb6d783f2e6"}],"tags":["csaf","vex","red-hat","cve.org"],"epss":0.0017,"epssPercentile":0.06731,"scores":{"vendor":7,"cna":7.8},"ingestedAt":"2026-09-14T15:23:07.473Z","slug":"CVE-2026-89638","body":"## Overview\n\nA flaw was found in the Linux kernel's Server Message Block (SMB) client. When a file with the setuid or setgid bit is written to on certain Common Internet File System (CIFS) mounts (specifically those using 'cifsacl', 'modefromsid' options, or SMB3.1.1 POSIX extensions), the kernel fails to properly clear these bits on the server. This oversight allows the setuid/setgid bits to persist, which could enable a local attacker to achieve unexpected privilege escalation upon subsequent execution of the affected file.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Important · affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4 · no fix planned: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4 · updated 2026-09-23 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89638.json)\n\n**kernel: smb: client: clear setuid/setgid bit on write with cifsacl/modefromsid/posix extensions** — rated Important by Red Hat. Released 2026-09-11, updated 2026-09-23.\n\nAffected:\n\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 8\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift Container Platform 4\n\nNo fix planned:\n\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 8\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift Container Platform 4\n\nNot affected:\n\n- Red Hat Enterprise Linux 6\n- Red Hat Enterprise Linux 7\n\n## Remediation\n\nAffected","depth":"twilight","depthScore":39,"depthScoreParts":{"impact":38.5,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":205542,"id":"CVE-2026-89638","ts":1789576724703,"field":"cvss","old":"7.3","new":"7"},{"seq":202841,"id":"CVE-2026-89638","ts":1789403732628,"field":"cvss","old":"7.8","new":"7.3"},{"seq":197824,"id":"CVE-2026-89638","ts":1789384320556,"field":"cvss","old":"7.3","new":"7.8"},{"seq":183398,"id":"CVE-2026-89638","ts":1789356675202,"field":"cvss","old":"7.8","new":"7.3"},{"seq":153480,"id":"CVE-2026-89638","ts":1789285350687,"field":"cvss","old":null,"new":"7.8"},{"seq":153479,"id":"CVE-2026-89638","ts":1789285350687,"field":"severity","old":"none","new":"high"},{"seq":147700,"id":"CVE-2026-89638","ts":1789270211935,"field":"cvss","old":null,"new":"7.3"},{"seq":147699,"id":"CVE-2026-89638","ts":1789270211935,"field":"severity","old":"none","new":"high"},{"seq":109460,"id":"CVE-2026-89638","ts":1789183732000,"field":"cvss","old":null,"new":"7.3"},{"seq":109459,"id":"CVE-2026-89638","ts":1789183732000,"field":"severity","old":"none","new":"high"}]}