CVE-2026-64137
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
19/07/2026
Last modified:
13/08/2026
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
smb: client: require net admin for CIFS SWN netlink<br />
<br />
CIFS_GENL_CMD_SWN_NOTIFY is the userspace witness-notify command. The<br />
intended sender is the cifs.witness helper, but the generic-netlink<br />
operation currently has no capability flag, so any local process can send<br />
RESOURCE_CHANGE or CLIENT_MOVE notifications to the in-kernel witness<br />
handler.<br />
<br />
The same family exposes CIFS_GENL_MCGRP_SWN without multicast-group<br />
capability flags. Register messages sent to that group include the witness<br />
registration id and, for NTLM-authenticated mounts, the username, domain,<br />
and password attributes copied from the CIFS session. An unprivileged<br />
local process should not be able to join that group and receive those<br />
messages.<br />
<br />
Require CAP_NET_ADMIN for incoming SWN_NOTIFY commands with<br />
GENL_ADMIN_PERM, and require CAP_NET_ADMIN over the network namespace for<br />
joining the SWN multicast group with GENL_MCAST_CAP_NET_ADMIN. The<br />
cifs.witness service runs with the privileges needed for both operations.
Impact
Base Score 3.x
7.80
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.11 (including) | 5.15.210 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.16 (including) | 6.1.176 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.2 (including) | 6.6.143 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.7 (including) | 6.12.92 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.13 (including) | 6.18.34 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.19 (including) | 7.0.11 (excluding) |
| cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc4:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/969bc6370334a5b4720c5470783295d6484bbc95
- https://git.kernel.org/stable/c/9919021a3b7974ae66a5f9915e3a48c10cfd409b
- https://git.kernel.org/stable/c/9cf7eb8919344932f909b2fac76296f7656fda8d
- https://git.kernel.org/stable/c/a3238b09c58f323e40743ce174cd0ab81b5c09ed
- https://git.kernel.org/stable/c/a8d17d22db591099519a89f14dd24810daba74c3
- https://git.kernel.org/stable/c/c2397b93fbb6f44a788fff30f99be2c20cc5e50f
- https://git.kernel.org/stable/c/d1ebfce2c1d161186a82e77590bf7da2ea1bce91



