9.1

CVE-2026-68457

ksmbd: use opener credentials for FSCTL mutations

In the Linux kernel, the following vulnerability has been resolved:

ksmbd: use opener credentials for FSCTL mutations

SET_SPARSE, SET_ZERO_DATA and SET_COMPRESSION operate on an open SMB
handle but call VFS xattr, fallocate or fileattr helpers with the current
ksmbd worker credentials. Those helpers can revalidate inode permissions,
ownership and LSM policy independently of the SMB handle access mask.

Run each operation with the credentials captured in the target file when
the handle was opened. Keep credential handling local to these single-file
FSCTLs rather than applying session credentials to the complete IOCTL
handler, which also contains handle-less and multi-handle operations.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9
Version < a8c18434e1f0d9f7989170bdb0490c0160baf065
Status affected
Version e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9
Version < 1e112c47ec5dd1942e2d4ca6e8e9b712238e20c2
Status affected
Version e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9
Version < fb1cae6302d58414ddf029e3f642711bd30243f7
Status affected
Version e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9
Version < e205f3e7e8c31a47cd11efb6cf663a527177e432
Status affected
Version e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9
Version < cfb2c6f71d61ed807c9d7a7af331d406f1f31877
Status affected
Version e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9
Version < c6394bcaf254c5baf9aff43376020be5db6d3316
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 5.15
Status affected
Version 0
Version < 5.15
Status unaffected
Version <= 6.1.*
Version 6.1.178
Status unaffected
Version <= 6.6.*
Version 6.6.145
Status unaffected
Version <= 6.12.*
Version 6.12.97
Status unaffected
Version <= 6.18.*
Version 6.18.40
Status unaffected
Version <= 7.1.*
Version 7.1.5
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.49% 0.396
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 9.1 3.9 5.2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/a8c18434e1f0d9f7989170bdb0490c0160baf065
https://git.kernel.org/stable/c/1e112c47ec5dd1942e2d4ca6e8e9b712238e20c2
https://git.kernel.org/stable/c/fb1cae6302d58414ddf029e3f642711bd30243f7
https://git.kernel.org/stable/c/e205f3e7e8c31a47cd11efb6cf663a527177e432
https://git.kernel.org/stable/c/cfb2c6f71d61ed807c9d7a7af331d406f1f31877
https://git.kernel.org/stable/c/c6394bcaf254c5baf9aff43376020be5db6d3316