CVE-2026-64392
Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
25/07/2026
Última modificación:
25/07/2026
Descripción
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
ksmbd: use opener credentials for delete-on-close<br />
<br />
Delete-on-close can be completed by deferred or durable handle teardown,<br />
where no request work is available. Both the base-file unlink and the ADS<br />
xattr removal consequently run with the ksmbd worker credentials and can<br />
bypass filesystem permission checks.<br />
<br />
Run both operations with the credentials captured in struct file when the<br />
handle was opened. This preserves the authenticated user&#39;s fsuid, fsgid,<br />
supplementary groups and capability restrictions at final close.
Impacto
Referencias a soluciones, herramientas e información
- https://git.kernel.org/stable/c/18c59109bb6fb816d5102171666f87cf1e29901d
- https://git.kernel.org/stable/c/4b7059974549d278e30fe70e2a4e421f9839817d
- https://git.kernel.org/stable/c/52e2f21911158ec961cd5aae19c56460db382af0
- https://git.kernel.org/stable/c/e72c15085b6d86f45d224d98aa75b5cace4aaab9
- https://git.kernel.org/stable/c/f08b3f451f12eee4abd8a5981803bc36db84458b



