CVE-2026-64396
- EPSS 0.17%
- Veröffentlicht 25.07.2026 08:50:40
- Zuletzt bearbeitet 04.09.2026 14:47:23
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix UAF of struct file_lock in SMB2_LOCK deferred-lock cancellation When a blocking byte-range lock request is deferred in the FILE_LOCK_DEFERRED path, ksmbd registers the a...
CVE-2026-64393
- EPSS 0.17%
- Veröffentlicht 25.07.2026 08:50:39
- Zuletzt bearbeitet 04.09.2026 19:08:35
In the Linux kernel, the following vulnerability has been resolved: ksmbd: run set info with opener credentials SMB2 SET_INFO handlers call path-based VFS helpers after checking the access mask granted to the SMB handle. Those helpers perform their...
CVE-2026-64394
- EPSS 0.18%
- Veröffentlicht 25.07.2026 08:50:39
- Zuletzt bearbeitet 04.09.2026 15:31:40
In the Linux kernel, the following vulnerability has been resolved: ksmbd: add a WRITE_DAC/WRITE_OWNER check to SMB2 SET_INFO SECURITY commit cc57232cae23 ("ksmbd: fix FSCTL permission bypass by adding a permission check for FSCTL_SET_SPARSE") adde...
CVE-2026-64391
- EPSS 0.17%
- Veröffentlicht 25.07.2026 08:50:38
- Zuletzt bearbeitet 04.09.2026 19:08:24
In the Linux kernel, the following vulnerability has been resolved: ksmbd: use opener credentials for ADS I/O Alternate data streams are stored as xattrs. Unlike regular file I/O, their read and write paths therefore call VFS xattr helpers which re...
CVE-2026-64392
- EPSS 0.18%
- Veröffentlicht 25.07.2026 08:50:38
- Zuletzt bearbeitet 04.09.2026 19:08:31
In the Linux kernel, the following vulnerability has been resolved: ksmbd: use opener credentials for delete-on-close Delete-on-close can be completed by deferred or durable handle teardown, where no request work is available. Both the base-file un...
CVE-2026-64390
- EPSS 0.18%
- Veröffentlicht 25.07.2026 08:50:37
- Zuletzt bearbeitet 04.09.2026 19:07:30
In the Linux kernel, the following vulnerability has been resolved: ksmbd: track the connection owning a byte-range lock SMB2_LOCK adds each granted byte-range lock to both the file lock list and the lock list of the connection which handled the re...
CVE-2026-64388
- EPSS 0.16%
- Veröffentlicht 25.07.2026 08:50:36
- Zuletzt bearbeitet 04.09.2026 20:42:42
In the Linux kernel, the following vulnerability has been resolved: smb/client: fix chown/chgrp with SMB3 POSIX Extensions Ownership (chown) and group (chgrp) modifications were being ignored when mounting with SMB3 POSIX Extensions unless CIFS_MOU...
CVE-2026-64389
- EPSS 0.21%
- Veröffentlicht 25.07.2026 08:50:36
- Zuletzt bearbeitet 04.09.2026 19:06:31
In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate NTLMv2 response before updating session key ksmbd_auth_ntlmv2() derives the NTLMv2 session key into sess->sess_key before it verifies the NTLMv2 response. ksmbd_dec...
CVE-2026-64387
- EPSS 0.17%
- Veröffentlicht 25.07.2026 08:50:35
- Zuletzt bearbeitet 04.09.2026 20:43:21
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix query directory replay double-free A response-bearing attempt can return a replayable error and free its response buffer. If SMB2_query_directory_init() fails befo...
CVE-2026-64386
- EPSS 0.17%
- Veröffentlicht 25.07.2026 08:50:34
- Zuletzt bearbeitet 04.09.2026 20:44:23
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix query_info() replay double-free A response-bearing attempt can return a replayable error and free its response buffer. If SMB2_query_info_init() fails before the n...