Executive brief
A security vulnerability was identified in the Linux kernel's ksmbd module, which provides SMB file sharing services. An attacker with limited access to a file share could bypass security restrictions to change file ownership or modify access control lists (ACLs). This could allow an unauthorized user to grant themselves full control over files they should only be able to view or minimally modify, potentially leading to data theft or unauthorized data modification.
Technical details
A vulnerability in the ksmbd module of the Linux kernel arises from a missing access check in the smb2_set_info_sec() function. While other file mutation operations in smb2_set_info_file() verify handle-level access (fp->daccess), the SECURITY arm lacked a check for FILE_WRITE_DAC or FILE_WRITE_OWNER permissions. An authenticated attacker with a handle carrying only FILE_WRITE_ATTRIBUTES could exploit this to rewrite a file's DACL or owner. Because this is a metadata/xattr operation, it bypasses the standard VFS FMODE_WRITE backstop. The issue has been resolved by adding the necessary WRITE_DAC/WRITE_OWNER permission gates in the SMB2 SET_INFO SECURITY path.
Affected products
- Linux Linux Kernel ksmbd module before fixed versions 6.1.99, 6.6.41, 6.9.10, and 6.10.0
Timeline
- 2026-06-09: disclosed: Vulnerability reported by Gil Portnoy
- 2026-07-24: patched: Fixes committed to stable kernel branches
- 2026-07-25: advisory: CVE-2026-64394 published
References
- https://git.kernel.org/stable/c/0848b1d8b403f530878195dcbe241a2fddb9d0e1
- https://git.kernel.org/stable/c/44df157a1183a7f746caa970c169255da5ac61f8
- https://git.kernel.org/stable/c/9ab2ffd3ed3d4ca1667c52de27026ddabc11e537
- https://git.kernel.org/stable/c/aae600cdaffc6d9ce97645f129799a103a97d06d
- https://git.kernel.org/stable/c/e6aa731f1b4b3e08caebf66a99f04b22bdab2e99
- https://git.kernel.org/stable/c/f56535db508ead8dec1c481ad93d7d8acd8f8f1e