CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-64388

highCVSS 7.8covered by 2 sourcesfirst seen 2026-07-25
In the Linux kernel, the following vulnerability has been resolved: smb/client: fix chown/chgrp with SMB3 POSIX Extensions Ownership (chown) and group (chgrp) modifications were being ignored when mounting with SMB3 POSIX Extensions unless CIFS_MOUNT_CIFS_ACL or CIFS_MOUNT_MODE_FROM_SID were also explicitly set. Fix this by checking for posix_extensions in cifs_setattr_nounix() when updating UID and GID, ensuring that id_mode_to_cifs_acl() is called to map and set the ownership/group information on the server.

CSIRTS triage

Other
What
The chown/chgrp operations with SMB3 POSIX Extensions are fixed.
Who is affected
Deployments using SMB client with POSIX Extensions.
Urgency
Remediation is necessary to maintain proper file permissions, with no known exploits.
Action
Apply the patch when it becomes available.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-64388

Get an email if CVE-2026-64388 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-64388

CVE.org record

Embed the live status

CVE-2026-64388 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-64388 status](https://www.csirts.com/badge/CVE-2026-64388)](https://www.csirts.com/cve/CVE-2026-64388)