CVE-2026-64391
ksmbd: use opener credentials for ADS I/O
CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th
In the Linux kernel, the following vulnerability has been resolved: ksmbd: use opener credentials for ADS I/O Alternate data streams are stored as xattrs. Unlike regular file I/O, their read and write paths therefore call VFS xattr helpers which recheck inode permissions and LSM policy using the current task credentials. Run ADS I/O with the credentials captured when the SMB handle was opened.
| Vendor | linux |
| Product | linux |
| Ecosystems | |
| Industries | Technology |
| Published | Jul 25, 2026 |
| Last Updated | Aug 5, 2026 |
Stay Ahead of the Next One
Get instant alerts for linux linux
Be the first to know when new critical vulnerabilities affecting linux linux are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
Linux / Linux
f44158485826c076335d6860d35872271a83791d < a8f5d39971bbad9340d49cd41b0e2da9452a649d f44158485826c076335d6860d35872271a83791d < 2b4592cea214683de0f2ce6f8c22c097fb0ea1ab f44158485826c076335d6860d35872271a83791d < 52a56cf53ec834c44ac1b4d16d585f26613ee5ce f44158485826c076335d6860d35872271a83791d < baa5e094886fffa7e6272edcb5e08be5ce28262c
Linux / Linux
5.15
References
git.kernel.org: https://git.kernel.org/stable/c/a8f5d39971bbad9340d49cd41b0e2da9452a649d git.kernel.org: https://git.kernel.org/stable/c/2b4592cea214683de0f2ce6f8c22c097fb0ea1ab git.kernel.org: https://git.kernel.org/stable/c/52a56cf53ec834c44ac1b4d16d585f26613ee5ce git.kernel.org: https://git.kernel.org/stable/c/baa5e094886fffa7e6272edcb5e08be5ce28262c