CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-64380

highCVSS 8.2covered by 2 sourcesfirst seen 2026-07-14
In the Linux kernel, the following vulnerability has been resolved: smb: client: harden POSIX SID length parsing posix_info_sid_size() reads sid[1] to obtain the subauthority count, but its existing boundary check still accepts buffers with only one remaining byte. Require two bytes before reading sid[1] so all client paths that reuse the helper reject truncated POSIX SIDs safely.

CSIRTS triage

What
The smb client has been hardened against POSIX SID length parsing issues.
Who is affected
Deployments of the smb client are affected.
Urgency
Remediation is necessary to prevent potential exploitation, although exploitation status is currently unknown.
Action
Update to the latest version of the smb client.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-64380

Get an email if CVE-2026-64380 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-64380

CVE.org record

Embed the live status

CVE-2026-64380 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-64380 status](https://www.csirts.com/badge/CVE-2026-64380)](https://www.csirts.com/cve/CVE-2026-64380)