CVE-2026-64391
In the Linux kernel, the following vulnerability has been resolved: ksmbd: use opener credentials for ADS I/O Alternate data streams are stored as xattrs. Unlike regular file I/O, their read and write paths therefore call VFS xattr helpers which recheck inode permissions and LSM policy using the current task credentials. Run ADS I/O with the credentials captured when the SMB handle was opened.
Affected versions
Fixed in
6.12.96,
6.18.39,
7.1.4,
7.2-rc1
and their respective stable series.
References
4 totalFrequently asked questions
-
What is CVE-2026-64391?
CVE-2026-64391 is a unscored severity Linux kernel vulnerability . CVE-2026-64391 has not been confirmed as actively exploited and is not listed in the CISA KEV catalog.
-
Is there a patch available for CVE-2026-64391?
Yes. CVE-2026-64391 has been patched. Fixed versions include 6.12.96, 6.18.39, 7.1.4 and others.
-
Is CVE-2026-64391 actively exploited?
No. CVE-2026-64391 has not been confirmed as actively exploited. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.