Incorrect Comparison in Linux kernel - CVE-2026-74521

 

Incorrect Comparison in Linux kernel - CVE-2026-74521

Published: August 16, 2026


Vulnerability identifier: #VU143256
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-74521
CWE-ID: CWE-697
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to bypass client identity checks.

The vulnerability exists due to improper comparison of fixed-size binary data in ksmbd SMB3 multichannel session binding and FSCTL_VALIDATE_NEGOTIATE_INFO handling when processing ClientGUID values. A remote user can send a crafted ClientGUID containing embedded NUL bytes to bypass client identity checks.


Affected software

Linux kernel
Ubuntu
linux-nvidia-tegra (Ubuntu package)

How to mitigate CVE-2026-74521

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3
linux-nvidia-tegra (Ubuntu package) - update to 6.8.0-1035.38

External References

Related Security Bulletins