Improper access control in Linux kernel - CVE-2026-64393
Published: July 27, 2026
Vulnerability details
The vulnerability allows a remote user to bypass intended permission checks.
The vulnerability exists due to improper access control in SMB2 SET_INFO handlers when processing SET_INFO requests. A remote user can send a specially crafted SET_INFO request to bypass intended permission checks.
The issue arises because path-based VFS helpers perform permission and LSM checks using worker credentials instead of the credentials captured when the file handle was opened.
Affected software
How to mitigate CVE-2026-64393
External References
- https://git.kernel.org/stable/c/0ce682867fd506f61f40c76bde7e4205bde34e87
- https://git.kernel.org/stable/c/20ee516a62989a8d505ee432f9e59525ea23984e
- https://git.kernel.org/stable/c/5cbabf3a71575cd31bc7785d92d4ab42338a654b
- https://git.kernel.org/stable/c/8cc9ec711f5255167247a9ab6a7179b787426ed7
- https://git.kernel.org/stable/c/b35afd5cf8fab236ef21117e42ee45691d4ffa7b
- https://git.kernel.org/stable/c/b383bcad3d2fe634b26efbce53e22bbb5753a520