CVE-2026-64392
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: use opener credentials for delete-on-close
Delete-on-close can be completed by deferred or durable handle teardown,
where no request work is available. Both the base-file unlink and the ADS
xattr removal consequently run with the ksmbd worker credentials and can
bypass filesystem permission checks.
Run both operations with the credentials captured in struct file when the
handle was opened. This preserves the authenticated user's fsuid, fsgid,
supplementary groups and capability restrictions at final close.
CSIRTS triage
- What
- The ksmbd service needs to use opener credentials for delete-on-close operations.
- Who is affected
- Deployments using ksmbd are affected.
- Urgency
- Remediation is necessary to ensure proper functionality, although exploitation status is currently unknown.
- Action
- Apply the fix for CVE-2026-64392.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2026-64392
Get an email if CVE-2026-64392 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Low exploitation risk0.47% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 38% of all EPSS-scored CVEs.
Advisory coverage (2)
- criticalCVE-2026-64392: In the Linux kernel, the following vulnerability has been resolved: ksmbd: use opener credenti…nvd · 2026-07-25
- highCVE-2026-64392: ksmbd: use opener credentials for delete-on-closemsrc · 2026-07-14
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-64392)