CVE-2026-64394

Description

A flaw was found in the Linux kernel's ksmbd component. This vulnerability allows a remote attacker to bypass intended access controls. By opening a file handle with limited write attributes, an attacker can use the SMB2 SET_INFO SECURITY operation to rewrite the file's access control list (DACL) and owner. This enables the attacker to grant themselves unauthorized permissions, leading to privilege escalation and potential unauthorized access to sensitive file operations.

Understanding the Weakness (CWE)

Access Control

Technical Impact: Gain Privileges or Assume Identity

A user can access restricted functionality and/or sensitive information that may include administrative functionality and user accounts.

Frequently Asked Questions

Want to get errata notifications? Sign up here.