---
id: CVE-2026-93191
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  smack: fix incorrect task context in smack_msg_queue_msgrcv

  The smack_msg_queue_msgrcv() function incorrectly checks
  the permissions of the 'current' task instead of t…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  smack: fix incorrect task context in smack_msg_queue_msgrcv

  The smack_msg_queue_msgrcv() function incorrectly checks
  the permissions of the 'current' task instead of t…
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= e114e473771c848c3cfec05f0123e70f1cdbdc99 <
    4e49f997ef0c569e09b42aab6bd38c7c54ea095d
  - >-
    Linux >= e114e473771c848c3cfec05f0123e70f1cdbdc99 <
    dbece6c2f80b0470d8d99d7a016827dce99ed6e3
  - >-
    Linux >= e114e473771c848c3cfec05f0123e70f1cdbdc99 <
    7be4bd21c50afa83c93799b0f16cf5bfa493194e
  - >-
    Linux >= e114e473771c848c3cfec05f0123e70f1cdbdc99 <
    ec47f4177046dfaaf1cebb15f4d2e7b543475daf
  - >-
    Linux >= e114e473771c848c3cfec05f0123e70f1cdbdc99 <
    e35dc5a4ed6d1e536382d80c685187511ff248a1
  - >-
    Linux >= e114e473771c848c3cfec05f0123e70f1cdbdc99 <
    c2ab27c2e11591524b1378c24ad18882a425d1fa
  - >-
    Linux >= e114e473771c848c3cfec05f0123e70f1cdbdc99 <
    d02c55e3ea82e41ea2c2026e08201e5daa4d0cfe
  - >-
    Linux >= e114e473771c848c3cfec05f0123e70f1cdbdc99 <
    fba3d32825f4bbc8e20f0cdc3b14df57965b8fe5
  - Linux 2.6.25
published: '2026-09-17'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T17:18:15.307'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-93191'
references:
  - url: 'https://git.kernel.org/stable/c/4e49f997ef0c569e09b42aab6bd38c7c54ea095d'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/7be4bd21c50afa83c93799b0f16cf5bfa493194e'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/c2ab27c2e11591524b1378c24ad18882a425d1fa'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/d02c55e3ea82e41ea2c2026e08201e5daa4d0cfe'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/dbece6c2f80b0470d8d99d7a016827dce99ed6e3'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/e35dc5a4ed6d1e536382d80c685187511ff248a1'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/ec47f4177046dfaaf1cebb15f4d2e7b543475daf'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/fba3d32825f4bbc8e20f0cdc3b14df57965b8fe5'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-17T16:21:47.725Z'
epss: 0.00196
epssPercentile: 0.0963
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

smack: fix incorrect task context in smack_msg_queue_msgrcv

The smack_msg_queue_msgrcv() function incorrectly checks
the permissions of the 'current' task instead of the
'target' task.

In the msgsnd() syscall path, if a receiver is already waiting,
the pipelined_send() optimization is used to push the message
directly to the receiver task:

    ipc/msg.c`pipelined_send():
    ` smp_store_release(&msr->r_msg, msg)

In this case, the 'sender' (current) task performs the check
on behalf of the 'receiver' task (msr->r_tsk, passed as the
'target' parameter):

  ipc/msg.c`pipelined_send():
  ` security_msg_queue_msgrcv(,, target := msr->r_tsk,,)

However, smack_msg_queue_msgrcv() ignores the 'target' and
checks 'current':

  smack_msg_queue_msgrcv(…)
  ` smk_curacc_msq(isp, MAY_READWRITE); // current task

'current' MAY satisfy smack_msg_queue_msgrcv r/w requirement,
but 'target' (the receiver task) might NOT;
as a result, an unauthorized receiver gets the message,
violating MAC policy.

Test:
1) create a sysv message queue with label “foo”
2) echo "bar foo r" >/smack/load2
3) msgrcv(,,,0,MSG_NOERROR) in "bar"-labeled task.
    The task is waiting for the messages ...
4) msgsnd() from a "foo"-labeled task:
"bar"-labeled task gets the message.

This patch fixes the issue by checking permission on the
'target' task instead of 'current'.

(2008-02-04, Casey Schaufler)

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
