Executive brief
A vulnerability was identified in the Linux kernel's ksmbd component, which provides SMB file sharing services. An authenticated user with limited permissions (such as the ability to only change file attributes) could exploit this flaw to delete or overwrite data in files they should not have permission to modify. This could lead to unauthorized data destruction or service disruption on affected file shares.
Technical details
A permission bypass vulnerability exists in the ksmbd SMB server within the Linux kernel. The function smb2_ioctl() processes the FSCTL_SET_ZERO_DATA command by calling ksmbd_vfs_zero_data(), which eventually invokes vfs_fallocate with PUNCH_HOLE or ZERO_RANGE. The implementation only verified share-level write permissions (KSMBD_TREE_CONN_FLAG_WRITABLE) but failed to check per-handle access rights (fp->daccess). Because handles opened with FILE_WRITE_ATTRIBUTES are internally opened as O_WRONLY, they bypass standard VFS write checks. An authenticated attacker can use such a handle to zero out file data despite lacking FILE_WRITE_DATA permissions. The issue has been addressed by adding a mandatory FILE_WRITE_DATA_LE check in the ioctl path.
Affected products
- Linux Linux Kernel 6.1.178, 6.6.145, 6.12.96, 6.18.39, 7.1-rc7
Timeline
- 2026-06-10: other: Vulnerability reported by Gil Portnoy
- 2026-06-16: patched: Initial fix committed to mainline kernel
- 2026-07-25: disclosed: CVE record published
References
- https://git.kernel.org/stable/c/25377f369688dd0bd814dc8965ed26d44238ecaa
- https://git.kernel.org/stable/c/3072d82461f498c85daea8766e9d8bfbada31605
- https://git.kernel.org/stable/c/3320ba068198adc144c89d6661b805acce01735b
- https://git.kernel.org/stable/c/57f2042fd87d7ce8fc3ac8b6c176e554df68b1a7
- https://git.kernel.org/stable/c/ca53bb17f4e8232cfaece3953d3cef62c559b039
- https://git.kernel.org/stable/c/deffa929086d7902e30918adf3dd27ccfe9c08b1