CVE-2026-64391: Linux Kernel

Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: ksmbd: use opener credentials for ADS I/O Alternate data streams are stored as xattrs. Unlike regular file I/O, their read and write paths therefore call VFS xattr helpers which recheck inode permissions and LSM policy using the current task credentials. Run ADS I/O with the credentials captured when the SMB handle was opened.

Affected products

  • Linux Linux Kernel: from 5.15, before 6.12.96 (fixed in 6.12.96); from 6.13, before 6.18.39 (fixed in 6.18.39); from 6.19, before 7.1.4 (fixed in 7.1.4)

Published 2026-07-25. Last modified 2026-09-04.