CVE-2026-64391

Source
https://cve.org/CVERecord?id=CVE-2026-64391
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64391.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-64391
Downstream
Related
Published
2026-07-25T08:50:38.013Z
Modified
2026-08-18T03:30:50.278147588Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
ksmbd: use opener credentials for ADS I/O
Details

In the Linux kernel, the following vulnerability has been resolved:

ksmbd: use opener credentials for ADS I/O

Alternate data streams are stored as xattrs. Unlike regular file I/O, their read and write paths therefore call VFS xattr helpers which recheck inode permissions and LSM policy using the current task credentials.

Run ADS I/O with the credentials captured when the SMB handle was opened.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64391.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
f44158485826c076335d6860d35872271a83791d
Fixed
a8f5d39971bbad9340d49cd41b0e2da9452a649d
Fixed
2b4592cea214683de0f2ce6f8c22c097fb0ea1ab
Fixed
52a56cf53ec834c44ac1b4d16d585f26613ee5ce
Fixed
baa5e094886fffa7e6272edcb5e08be5ce28262c

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64391.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.15.0
Fixed
6.12.96
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.39
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64391.json"