---
id: CVE-2026-89638
title: >-
  kernel: smb: client: clear setuid/setgid bit on write with
  cifsacl/modefromsid/posix extensions (CVE-2026-89638)
summary: >-
  A flaw was found in the Linux kernel's Server Message Block (SMB) client. When
  a file with the setuid or setgid bit is written to on certain Common Internet
  File System (CIFS) mounts (specifically those using 'cifsacl', 'modefromsid'
  optio…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cvssSource: vendor
cwe: CWE-281
vendor: Red Hat
product: Red Hat Enterprise Linux 9
affected:
  - enterprise_linux 10
  - enterprise_linux 8
  - enterprise_linux 9
published: '2026-09-11'
updated: '2026-09-27'
sourceUpdated: '2026-09-27T07:14:03+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89638.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89638.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-89638'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2532122'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-89638'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-89638'
  - url: >-
      https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-89638.mbox
  - url: 'https://git.kernel.org/stable/c/69bfe810ecd1e0387d8975d711cd326341d13c6e'
  - url: 'https://git.kernel.org/stable/c/b10015807e4c628095d1d1d1c9307efc8cdd9e1b'
  - url: 'https://git.kernel.org/stable/c/b8e5dc4f95e5484159b343903f302eb6d783f2e6'
tags:
  - csaf
  - vex
  - red-hat
  - cve.org
epss: 0.00182
epssPercentile: 0.07012
scores:
  vendor: 7
  cna: 7.8
ingestedAt: '2026-09-14T15:23:07.473Z'
---

## Overview

A flaw was found in the Linux kernel's Server Message Block (SMB) client. When a file with the setuid or setgid bit is written to on certain Common Internet File System (CIFS) mounts (specifically those using 'cifsacl', 'modefromsid' options, or SMB3.1.1 POSIX extensions), the kernel fails to properly clear these bits on the server. This oversight allows the setuid/setgid bits to persist, which could enable a local attacker to achieve unexpected privilege escalation upon subsequent execution of the affected file.

## Vendor advisories

- **Red Hat VEX** · Important · affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9 · no fix planned: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9 · updated 2026-09-27 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89638.json)

**kernel: smb: client: clear setuid/setgid bit on write with cifsacl/modefromsid/posix extensions** — rated Important by Red Hat. Released 2026-09-11, updated 2026-09-27.

Affected:

- Red Hat Enterprise Linux 10
- Red Hat Enterprise Linux 8
- Red Hat Enterprise Linux 9

No fix planned:

- Red Hat Enterprise Linux 10
- Red Hat Enterprise Linux 8
- Red Hat Enterprise Linux 9

Not affected:

- Red Hat Enterprise Linux 6
- Red Hat Enterprise Linux 7

## Remediation

Affected

Workarounds / mitigations:

- Mount SMB/CIFS shares with the `nosuid` mount option to prevent setuid and setgid binaries from executing with elevated permissions, or prevent the `cifs` module from loading if network SMB shares are not needed.

1. Apply `nosuid` to an active mount point:
```
mount -o remount,nosuid /path/to/cifs/mount
```

2. Persist this setting by ensuring `nosuid` is present in the mount options within `/etc/fstab`:
```
//server/share /mnt/cifs cifs credentials=/etc/samba/creds,nosuid 0 0
```

3. Alternat…
