Improper access control in Linux kernel - CVE-2026-64298
Published: July 27, 2026
Vulnerability details
The vulnerability allows a local user to bypass file write permission checks and truncate a file.
The vulnerability exists due to improper access control in nfs_open_permission_mask() when handling open requests with O_TRUNC on NFSv4 delegated opens. A local user can open a file with O_RDONLY | O_TRUNC to bypass file write permission checks and truncate a file.
This issue occurs when the client satisfies the OPEN locally from a cached write delegation and then sends truncation to the server using delegation state.
Affected software
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for x86_64
Red Hat Enterprise Linux for Real Time
Red Hat Enterprise Linux for Real Time for NFV
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
openEuler
Ubuntu
kernel (Red Hat package)
kernel-rt (Red Hat package)
kernel-tools-devel
python3-perf-debuginfo
python3-perf
perf-debuginfo
perf
kernel-tools-debuginfo
kernel-tools
kernel-source
kernel-extra-modules
kernel-devel
kernel-debugsource
kernel-debuginfo
bpftool-debuginfo
bpftool
kernel
kernel-headers
linux (Ubuntu package)
linux-gcp-7.0 (Ubuntu package)
linux-oem-7.0 (Ubuntu package)
How to mitigate CVE-2026-64298
kernel (Red Hat package) - addressed in versions 4.18.0-553.159.1.el8_10, 6.12.0-211.50.1.el10_2
kernel-rt (Red Hat package) - update to 4.18.0-553.159.1.rt7.500.el8_10
kernel-tools-devel - update to 6.6.0-145.3.29.160
python3-perf-debuginfo - update to 6.6.0-145.3.29.160
python3-perf - update to 6.6.0-145.3.29.160
perf-debuginfo - update to 6.6.0-145.3.29.160
perf - update to 6.6.0-145.3.29.160
kernel-tools-debuginfo - update to 6.6.0-145.3.29.160
kernel-tools - update to 6.6.0-145.3.29.160
kernel-source - update to 6.6.0-145.3.29.160
kernel-extra-modules - update to 6.6.0-145.3.29.160
kernel-devel - update to 6.6.0-145.3.29.160
kernel-debugsource - update to 6.6.0-145.3.29.160
kernel-debuginfo - update to 6.6.0-145.3.29.160
bpftool-debuginfo - update to 6.6.0-145.3.29.160
bpftool - update to 6.6.0-145.3.29.160
kernel - update to 6.6.0-145.3.29.160
kernel-headers - update to 6.6.0-145.3.29.160
linux (Ubuntu package) - addressed in versions 7.0.0-31.31, 7.0.0-31.31.1, 7.0.0-31.31~24.04.1, 7.0.0-1006.7, 7.0.0-1011.11~24.04.1, 7.0.0-1012.12, 7.0.0-1012.12~24.04.1
linux-gcp-7.0 (Ubuntu package) - update to 7.0.0-1011.11~24.04.1
linux-oem-7.0 (Ubuntu package) - update to 7.0.0-1013.13
External References
- https://git.kernel.org/stable/c/22c1fd1355ad4ca27aa7f0fa02719122dd92d9de
- https://git.kernel.org/stable/c/30fdf4df6c3c00efec947e4ddf97f0fdd4473628
- https://git.kernel.org/stable/c/4817c8974315b666e895b7d1bb83cd3664c323b1
- https://git.kernel.org/stable/c/5140f099ecd8a2f2808b7f7b720ee1bad8468974
- https://git.kernel.org/stable/c/6bd7d0a06b53c4e797e1a9cea0d2d41aa1b26230
- https://git.kernel.org/stable/c/a937e92c1d00534b5c2e3e9f4381b7e988180797
- https://git.kernel.org/stable/c/cb148a2762d644bff1894728e8835a9a4b84f9ea
- https://git.kernel.org/stable/c/e36501b7d4abdcd6d69a7cb901b2f286b7a3d041
Related Security Bulletins
- Improper access control in Linux kernel nfs
- Red Hat Enterprise Linux 10 update for kernel
- Red Hat Enterprise Linux 8 update for kernel-rt
- Red Hat Enterprise Linux 8 update for kernel
- openEuler 24.03 LTS SP3 update for kernel
- Ubuntu update for linux-oem-7.0
- Ubuntu update for linux
- Ubuntu update for linux-gcp-7.0