๐Ÿ” CVE Alert

CVE-2026-64398

UNKNOWN 0.0

ksmbd: add a permission check for FSCTL_SET_ZERO_DATA

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: ksmbd: add a permission check for FSCTL_SET_ZERO_DATA FSCTL_SET_ZERO_DATA in smb2_ioctl() destroys file data via ksmbd_vfs_zero_data() -> vfs_fallocate(PUNCH_HOLE/ZERO_RANGE) after checking only the share-level KSMBD_TREE_CONN_FLAG_WRITABLE, with no per-handle access check. A handle opened with only FILE_WRITE_ATTRIBUTES still yields an FMODE_WRITE filp (FILE_WRITE_ATTRIBUTES is part of FILE_WRITE_DESIRE_ACCESS_LE, so smb2_create_open_flags() opens it O_WRONLY), so the vfs_fallocate FMODE_WRITE check does not stop it; only the missing fp->daccess gate would. Reproduced on mainline 7.1-rc7 with KASAN by an authenticated SMB client: a FILE_WRITE_ATTRIBUTES-only handle zeroed 4096 bytes of file data it had no FILE_WRITE_DATA right to (6/6; a FILE_READ_DATA-only handle was correctly denied). This is the unfixed sibling of commit cc57232cae23 ("ksmbd: fix FSCTL permission bypass by adding a permission check for FSCTL_SET_SPARSE"). Because SET_ZERO_DATA writes data (not an attribute), require FILE_WRITE_DATA.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Jul 25, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 25377f369688dd0bd814dc8965ed26d44238ecaa 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 3072d82461f498c85daea8766e9d8bfbada31605 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < ca53bb17f4e8232cfaece3953d3cef62c559b039 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 57f2042fd87d7ce8fc3ac8b6c176e554df68b1a7 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < deffa929086d7902e30918adf3dd27ccfe9c08b1 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 3320ba068198adc144c89d6661b805acce01735b 0 < 6.1.178 0 < 6.6.145 0 < 6.12.96 0 < 6.18.39 0 < 7.1.4
Linux / Linux
All versions affected

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/25377f369688dd0bd814dc8965ed26d44238ecaa git.kernel.org: https://git.kernel.org/stable/c/3072d82461f498c85daea8766e9d8bfbada31605 git.kernel.org: https://git.kernel.org/stable/c/ca53bb17f4e8232cfaece3953d3cef62c559b039 git.kernel.org: https://git.kernel.org/stable/c/57f2042fd87d7ce8fc3ac8b6c176e554df68b1a7 git.kernel.org: https://git.kernel.org/stable/c/deffa929086d7902e30918adf3dd27ccfe9c08b1 git.kernel.org: https://git.kernel.org/stable/c/3320ba068198adc144c89d6661b805acce01735b