Executive brief
A security issue was identified in the Linux kernel's SMB client where certain network communication channels lacked proper permission checks. This allowed unprivileged local users to intercept sensitive information, including usernames and passwords for network file shares, or send unauthorized commands that could disrupt network connections. The issue has been resolved by requiring administrative privileges for these specific network operations.
Technical details
A vulnerability in the Linux kernel's SMB client (cifs) stems from missing capability flags in the Generic Netlink implementation for the Service Witness Protocol (SWN). Specifically, the CIFS_GENL_CMD_SWN_NOTIFY command and the CIFS_GENL_MCGRP_SWN multicast group lacked GENL_ADMIN_PERM and GENL_MCAST_CAP_NET_ADMIN flags, respectively. This allowed any local unprivileged process to send spoofed RESOURCE_CHANGE or CLIENT_MOVE notifications to the kernel or join the multicast group to receive registration messages containing witness IDs and NTLM credentials (username, domain, and password). The fix enforces CAP_NET_ADMIN for these operations.
Affected products
- Linux Linux Kernel fed979a7e082 to 9cf7eb891934, 9919021a3b79, 969bc6370334, a3238b09c58f, a8d17d22db59, c2397b93fbb6, d1ebfce2c1d1
Timeline
- 2026-05-29: disclosed: Initial patch authored
- 2026-06-19: patched: Patch committed to stable tree
- 2026-07-19: advisory: CVE published
References
- https://git.kernel.org/stable/c/969bc6370334a5b4720c5470783295d6484bbc95
- https://git.kernel.org/stable/c/9919021a3b7974ae66a5f9915e3a48c10cfd409b
- https://git.kernel.org/stable/c/9cf7eb8919344932f909b2fac76296f7656fda8d
- https://git.kernel.org/stable/c/a3238b09c58f323e40743ce174cd0ab81b5c09ed
- https://git.kernel.org/stable/c/a8d17d22db591099519a89f14dd24810daba74c3
- https://git.kernel.org/stable/c/c2397b93fbb6f44a788fff30f99be2c20cc5e50f
- https://git.kernel.org/stable/c/d1ebfce2c1d161186a82e77590bf7da2ea1bce91