Skip to content
CVSS 9.8 · CRITICAL

CVE-2026-64391Critical RCE in Linux kernel SMB server (ksmbd)

In the Linux kernel, the following vulnerability has been resolved: ksmbd: use opener credentials for ADS I/O Alternate data streams are stored as xattrs. Unlike regular file I/O, their read and write paths therefore call VFS xattr helpers which recheck inode permissions and LSM policy using the current task credentials. Run ADS I/O with the credentials captured when the SMB handle was opened.

View on NVD

Analysis

A critical vulnerability was found in the Linux kernel SMB server (ksmbd). The flaw involves improper credential handling for Alternate Data Streams, which can lead to unauthorized access or remote code execution on systems running this service.

Relevant roles

LinuxBackendCloudDockerKubernetesCyberSecurity

Severity

Score: 9.8(CRITICAL)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AV: NETWORK
AC: LOW
PR: NONE
UI: NONE
S: UNCHANGED
C: HIGH
I: HIGH
A: HIGH

EPSS

Probability of exploitation (next 30 days): 0.0017 (0.2%)
Percentile: 6.4%
EPSS: 2026-07-26

Technical description

In the Linux kernel, the following vulnerability has been resolved: ksmbd: use opener credentials for ADS I/O Alternate data streams are stored as xattrs. Unlike regular file I/O, their read and write paths therefore call VFS xattr helpers which recheck inode permissions and LSM policy using the current task credentials. Run ADS I/O with the credentials captured when the SMB handle was opened.

Published: 7/25/2026, 10:17:22 AM
Last modified: 7/27/2026, 5:16:45 AM

References

HomeEventsBlogResourcesCoursesTeam