Improper access control in Linux kernel - CVE-2026-64395
Published: July 27, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in FSCTL_DUPLICATE_EXTENTS_TO_FILE handling in ksmbd when processing duplicate extents requests. A remote user can use a source handle opened without read access to copy file contents into an attacker-readable destination to disclose sensitive information.
The issue affects the source file access check before invoking file range clone or copy operations.
Affected software
Ubuntu
linux (Ubuntu package)
linux-azure (Ubuntu package)
linux-gcp-7.0 (Ubuntu package)
linux-oracle-7.0 (Ubuntu package)
linux-oem-7.0 (Ubuntu package)
linux-azure-7.0 (Ubuntu package)
How to mitigate CVE-2026-64395
linux (Ubuntu package) - addressed in versions 7.0.0-31.31, 7.0.0-31.31.1, 7.0.0-31.31~24.04.1, 7.0.0-1006.7, 7.0.0-1011.11~24.04.1, 7.0.0-1012.12, 7.0.0-1012.12~24.04.1
linux-azure (Ubuntu package) - addressed in versions 7.0.0-1011.11, 7.0.0-1014.14
linux-gcp-7.0 (Ubuntu package) - update to 7.0.0-1011.11~24.04.1
linux-oracle-7.0 (Ubuntu package) - update to 7.0.0-1011.11~24.04.1
linux-oem-7.0 (Ubuntu package) - update to 7.0.0-1013.13
linux-azure-7.0 (Ubuntu package) - update to 7.0.0-1014.14~24.04.1
External References
- https://git.kernel.org/stable/c/2d2ab6983620c2d60ce7db72133984ca3873b929
- https://git.kernel.org/stable/c/67bdad9cf01b25030e3bf00bbce6c309319d6663
- https://git.kernel.org/stable/c/a10942af27832c2761d020863a46e79bebe0567d
- https://git.kernel.org/stable/c/b0d4d5cb846a1ddb7aaab9adfb5986e4540e6e5f
- https://git.kernel.org/stable/c/cedff600f1642aa982178503552f0d007bc829c8
- https://git.kernel.org/stable/c/db231af842868268839f9f9619c68cb27830d8be