๐Ÿ” CVE Alert

CVE-2026-64399

CRITICAL 9.8

ksmbd: add permission checks for FSCTL_DUPLICATE_EXTENTS_TO_FILE

CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: ksmbd: add permission checks for FSCTL_DUPLICATE_EXTENTS_TO_FILE The FSCTL_DUPLICATE_EXTENTS_TO_FILE arm of smb2_ioctl() overwrites the destination file's data via vfs_clone_file_range() with neither the share-level KSMBD_TREE_CONN_FLAG_WRITABLE check nor a per-handle fp->daccess check that the other write-bearing arms carry. A client can overwrite destination data on a read-only share, or from a handle opened with only FILE_WRITE_ATTRIBUTES (which still yields an FMODE_WRITE filp). FILE_WRITE_ATTRIBUTES-only destination handle overwrote the file's data via the clone. Add both checks, matching the FSCTL_SET_SPARSE permission fix; require FILE_WRITE_DATA since this writes data.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Jul 25, 2026
Last Updated Aug 5, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new critical vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Linux / Linux
eb817368f50c1cbe1bd07044124aad7db6330e3a < bf460ad5958d506492de4524a656439da3f99c51 eb817368f50c1cbe1bd07044124aad7db6330e3a < 620d133d469295ee7c017ca6aafac335f65c4a5a eb817368f50c1cbe1bd07044124aad7db6330e3a < 9b9cf7e65cbeaae1b6636144bacee611cdd7a5d6 eb817368f50c1cbe1bd07044124aad7db6330e3a < baae7b39673ec21073a25e3d14f8feaada01d5df eb817368f50c1cbe1bd07044124aad7db6330e3a < c917e4522d251071dde9871b9142d8ea1186ebfe eb817368f50c1cbe1bd07044124aad7db6330e3a < 388e4139db27a9e3612c9d356b826f5b1ff6a9e3
Linux / Linux
5.15

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/bf460ad5958d506492de4524a656439da3f99c51 git.kernel.org: https://git.kernel.org/stable/c/620d133d469295ee7c017ca6aafac335f65c4a5a git.kernel.org: https://git.kernel.org/stable/c/9b9cf7e65cbeaae1b6636144bacee611cdd7a5d6 git.kernel.org: https://git.kernel.org/stable/c/baae7b39673ec21073a25e3d14f8feaada01d5df git.kernel.org: https://git.kernel.org/stable/c/c917e4522d251071dde9871b9142d8ea1186ebfe git.kernel.org: https://git.kernel.org/stable/c/388e4139db27a9e3612c9d356b826f5b1ff6a9e3