CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-64392

criticalCVSS 9.1covered by 2 sourcesfirst seen 2026-07-14
In the Linux kernel, the following vulnerability has been resolved: ksmbd: use opener credentials for delete-on-close Delete-on-close can be completed by deferred or durable handle teardown, where no request work is available. Both the base-file unlink and the ADS xattr removal consequently run with the ksmbd worker credentials and can bypass filesystem permission checks. Run both operations with the credentials captured in struct file when the handle was opened. This preserves the authenticated user's fsuid, fsgid, supplementary groups and capability restrictions at final close.

CSIRTS triage

What
The ksmbd service needs to use opener credentials for delete-on-close operations.
Who is affected
Deployments using ksmbd are affected.
Urgency
Remediation is necessary to ensure proper functionality, although exploitation status is currently unknown.
Action
Apply the fix for CVE-2026-64392.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-64392

Get an email if CVE-2026-64392 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-64392

CVE.org record

Embed the live status

CVE-2026-64392 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-64392 status](https://www.csirts.com/badge/CVE-2026-64392)](https://www.csirts.com/cve/CVE-2026-64392)