Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-64137

Gravedad CVSS v3.1:
ALTA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
19/07/2026
Última modificación:
13/08/2026

Descripción

*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> smb: client: require net admin for CIFS SWN netlink<br /> <br /> CIFS_GENL_CMD_SWN_NOTIFY is the userspace witness-notify command. The<br /> intended sender is the cifs.witness helper, but the generic-netlink<br /> operation currently has no capability flag, so any local process can send<br /> RESOURCE_CHANGE or CLIENT_MOVE notifications to the in-kernel witness<br /> handler.<br /> <br /> The same family exposes CIFS_GENL_MCGRP_SWN without multicast-group<br /> capability flags. Register messages sent to that group include the witness<br /> registration id and, for NTLM-authenticated mounts, the username, domain,<br /> and password attributes copied from the CIFS session. An unprivileged<br /> local process should not be able to join that group and receive those<br /> messages.<br /> <br /> Require CAP_NET_ADMIN for incoming SWN_NOTIFY commands with<br /> GENL_ADMIN_PERM, and require CAP_NET_ADMIN over the network namespace for<br /> joining the SWN multicast group with GENL_MCAST_CAP_NET_ADMIN. The<br /> cifs.witness service runs with the privileges needed for both operations.

Productos y versiones vulnerables

CPE Desde Hasta
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.11 (incluyendo) 5.15.210 (excluyendo)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.16 (incluyendo) 6.1.176 (excluyendo)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.2 (incluyendo) 6.6.143 (excluyendo)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.7 (incluyendo) 6.12.92 (excluyendo)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.13 (incluyendo) 6.18.34 (excluyendo)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.19 (incluyendo) 7.0.11 (excluyendo)
cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc4:*:*:*:*:*:*