CVE-2026-64395

Source
https://cve.org/CVERecord?id=CVE-2026-64395
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64395.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-64395
Downstream
Published
2026-07-25T08:50:40.393Z
Modified
2026-07-28T04:02:54.349871575Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
ksmbd: require source read access for duplicate extents
Details

In the Linux kernel, the following vulnerability has been resolved:

ksmbd: require source read access for duplicate extents

FSCTLDUPLICATEEXTENTSTOFILE passes the source file directly to vfsclonefilerange() or vfscopyfilerange() without checking the SMB access mask granted to the source handle. A handle opened with attribute access can consequently be used to copy file contents into an attacker-readable destination.

Require FILEREADDATA on the source handle before either VFS operation, matching other ksmbd data-copy paths.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64395.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
eb817368f50c1cbe1bd07044124aad7db6330e3a
Fixed
2d2ab6983620c2d60ce7db72133984ca3873b929
Fixed
67bdad9cf01b25030e3bf00bbce6c309319d6663
Fixed
b0d4d5cb846a1ddb7aaab9adfb5986e4540e6e5f
Fixed
db231af842868268839f9f9619c68cb27830d8be
Fixed
a10942af27832c2761d020863a46e79bebe0567d
Fixed
cedff600f1642aa982178503552f0d007bc829c8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64395.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.15.0
Fixed
6.1.178
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.145
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.96
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.39
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64395.json"