CVE-2026-64393
Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
25/07/2026
Última modificación:
25/07/2026
Descripción
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
ksmbd: run set info with opener credentials<br />
<br />
SMB2 SET_INFO handlers call path-based VFS helpers after checking the<br />
access mask granted to the SMB handle. Those helpers perform their owner,<br />
inode permission and LSM checks using the current ksmbd worker credentials.<br />
<br />
Run the complete SET_INFO dispatch with the credentials captured when the<br />
handle was opened. This also removes the separate security information<br />
credential setup and keeps all SET_INFO classes under one credential scope.<br />
<br />
Direct override_creds() is used because it can nest with the request<br />
credential overrides already used by rename and link helpers.
Impacto
Referencias a soluciones, herramientas e información
- https://git.kernel.org/stable/c/0ce682867fd506f61f40c76bde7e4205bde34e87
- https://git.kernel.org/stable/c/20ee516a62989a8d505ee432f9e59525ea23984e
- https://git.kernel.org/stable/c/5cbabf3a71575cd31bc7785d92d4ab42338a654b
- https://git.kernel.org/stable/c/8cc9ec711f5255167247a9ab6a7179b787426ed7
- https://git.kernel.org/stable/c/b35afd5cf8fab236ef21117e42ee45691d4ffa7b
- https://git.kernel.org/stable/c/b383bcad3d2fe634b26efbce53e22bbb5753a520



