๐Ÿ” CVE Alert

CVE-2026-64395

HIGH 7.5

ksmbd: require source read access for duplicate extents

CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: ksmbd: require source read access for duplicate extents FSCTL_DUPLICATE_EXTENTS_TO_FILE passes the source file directly to vfs_clone_file_range() or vfs_copy_file_range() without checking the SMB access mask granted to the source handle. A handle opened with attribute access can consequently be used to copy file contents into an attacker-readable destination. Require FILE_READ_DATA on the source handle before either VFS operation, matching other ksmbd data-copy paths.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Jul 25, 2026
Last Updated Aug 5, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new high vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Linux / Linux
eb817368f50c1cbe1bd07044124aad7db6330e3a < 2d2ab6983620c2d60ce7db72133984ca3873b929 eb817368f50c1cbe1bd07044124aad7db6330e3a < 67bdad9cf01b25030e3bf00bbce6c309319d6663 eb817368f50c1cbe1bd07044124aad7db6330e3a < b0d4d5cb846a1ddb7aaab9adfb5986e4540e6e5f eb817368f50c1cbe1bd07044124aad7db6330e3a < db231af842868268839f9f9619c68cb27830d8be eb817368f50c1cbe1bd07044124aad7db6330e3a < a10942af27832c2761d020863a46e79bebe0567d eb817368f50c1cbe1bd07044124aad7db6330e3a < cedff600f1642aa982178503552f0d007bc829c8
Linux / Linux
5.15

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/2d2ab6983620c2d60ce7db72133984ca3873b929 git.kernel.org: https://git.kernel.org/stable/c/67bdad9cf01b25030e3bf00bbce6c309319d6663 git.kernel.org: https://git.kernel.org/stable/c/b0d4d5cb846a1ddb7aaab9adfb5986e4540e6e5f git.kernel.org: https://git.kernel.org/stable/c/db231af842868268839f9f9619c68cb27830d8be git.kernel.org: https://git.kernel.org/stable/c/a10942af27832c2761d020863a46e79bebe0567d git.kernel.org: https://git.kernel.org/stable/c/cedff600f1642aa982178503552f0d007bc829c8