CVE-2026-64400
- EPSS 0.2%
- Veröffentlicht 25.07.2026 08:50:43
- Zuletzt bearbeitet 04.09.2026 14:46:32
In the Linux kernel, the following vulnerability has been resolved: ksmbd: prevent path traversal bypass by restricting caseless retry ksmbd_vfs_path_lookup() enforces LOOKUP_BENEATH to restrict path resolution within the share root. When a crafted...
CVE-2026-64398
- EPSS 0.18%
- Veröffentlicht 25.07.2026 08:50:42
- Zuletzt bearbeitet 04.09.2026 14:46:57
In the Linux kernel, the following vulnerability has been resolved: ksmbd: add a permission check for FSCTL_SET_ZERO_DATA FSCTL_SET_ZERO_DATA in smb2_ioctl() destroys file data via ksmbd_vfs_zero_data() -> vfs_fallocate(PUNCH_HOLE/ZERO_RANGE) after...
CVE-2026-64399
- EPSS 0.17%
- Veröffentlicht 25.07.2026 08:50:42
- Zuletzt bearbeitet 04.09.2026 14:46:44
In the Linux kernel, the following vulnerability has been resolved: ksmbd: add permission checks for FSCTL_DUPLICATE_EXTENTS_TO_FILE The FSCTL_DUPLICATE_EXTENTS_TO_FILE arm of smb2_ioctl() overwrites the destination file's data via vfs_clone_file_r...
CVE-2026-64397
- EPSS 0.17%
- Veröffentlicht 25.07.2026 08:50:41
- Zuletzt bearbeitet 04.09.2026 14:47:10
In the Linux kernel, the following vulnerability has been resolved: ksmbd: serialize QUERY_DIRECTORY requests per file smb2_query_dir() stores a pointer to its stack-allocated private data in the ksmbd_file readdir_data. Concurrent QUERY_DIRECTORY ...
CVE-2026-64395
- EPSS 0.17%
- Veröffentlicht 25.07.2026 08:50:40
- Zuletzt bearbeitet 04.09.2026 14:47:48
In the Linux kernel, the following vulnerability has been resolved: ksmbd: require source read access for duplicate extents FSCTL_DUPLICATE_EXTENTS_TO_FILE passes the source file directly to vfs_clone_file_range() or vfs_copy_file_range() without c...
CVE-2026-64396
- EPSS 0.17%
- Veröffentlicht 25.07.2026 08:50:40
- Zuletzt bearbeitet 04.09.2026 14:47:23
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix UAF of struct file_lock in SMB2_LOCK deferred-lock cancellation When a blocking byte-range lock request is deferred in the FILE_LOCK_DEFERRED path, ksmbd registers the a...
CVE-2026-64393
- EPSS 0.17%
- Veröffentlicht 25.07.2026 08:50:39
- Zuletzt bearbeitet 04.09.2026 19:08:35
In the Linux kernel, the following vulnerability has been resolved: ksmbd: run set info with opener credentials SMB2 SET_INFO handlers call path-based VFS helpers after checking the access mask granted to the SMB handle. Those helpers perform their...
CVE-2026-64394
- EPSS 0.18%
- Veröffentlicht 25.07.2026 08:50:39
- Zuletzt bearbeitet 04.09.2026 15:31:40
In the Linux kernel, the following vulnerability has been resolved: ksmbd: add a WRITE_DAC/WRITE_OWNER check to SMB2 SET_INFO SECURITY commit cc57232cae23 ("ksmbd: fix FSCTL permission bypass by adding a permission check for FSCTL_SET_SPARSE") adde...
CVE-2026-64391
- EPSS 0.17%
- Veröffentlicht 25.07.2026 08:50:38
- Zuletzt bearbeitet 04.09.2026 19:08:24
In the Linux kernel, the following vulnerability has been resolved: ksmbd: use opener credentials for ADS I/O Alternate data streams are stored as xattrs. Unlike regular file I/O, their read and write paths therefore call VFS xattr helpers which re...
CVE-2026-64392
- EPSS 0.18%
- Veröffentlicht 25.07.2026 08:50:38
- Zuletzt bearbeitet 04.09.2026 19:08:31
In the Linux kernel, the following vulnerability has been resolved: ksmbd: use opener credentials for delete-on-close Delete-on-close can be completed by deferred or durable handle teardown, where no request work is available. Both the base-file un...