CVE-2026-64137: smb: client: require net admin for CIFS SWN netlink

Published Jul 19, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

smb: client: require net admin for CIFS SWN netlink

CIFSGENLCMDSWNNOTIFY is the userspace witness-notify command. The intended sender is the cifs.witness helper, but the generic-netlink operation currently has no capability flag, so any local process can send RESOURCECHANGE or CLIENTMOVE notifications to the in-kernel witness handler.

The same family exposes CIFSGENLMCGRPSWN without multicast-group capability flags. Register messages sent to that group include the witness registration id and, for NTLM-authenticated mounts, the username, domain, and password attributes copied from the CIFS session. An unprivileged local process should not be able to join that group and receive those messages.

Require CAPNETADMIN for incoming SWNNOTIFY commands with GENLADMINPERM, and require CAPNETADMIN over the network namespace for joining the SWN multicast group with GENLMCASTCAPNETADMIN. The cifs.witness service runs with the privileges needed for both operations.

Affected Software

11 affected components
Linux Linux kernel
Linux Linux kernel>=5.11<5.15.210
Linux Linux kernel>=5.16<6.1.176
Linux Linux kernel>=6.2<6.6.143
Linux Linux kernel>=6.7<6.12.92
Linux Linux kernel>=6.13<6.18.34
Linux Linux kernel>=6.19<7.0.11
Linux Linux kernel=7.1-rc1
Linux Linux kernel=7.1-rc2
Linux Linux kernel=7.1-rc3
Linux Linux kernel=7.1-rc4

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Update/enable the kernel change so incoming SWN_NOTIFY (CIFS_GENL_CMD_SWN_NOTIFY) commands require CAP_NET_ADMIN over the network namespace, preventing unprivileged local processes from registering/sending witness-notify messages.

    Linux kernel CIFS witness generic-netlink (CIFS_GENL_CMD_SWN_NOTIFY / SWN_NOTIFY) Require CAP_NET_ADMIN for incoming SWN_NOTIFY commands = CAP_NET_ADMIN required (network namespace)
  2. Configuration

    Update/enable the kernel behavior so joining the SWN multicast group requires GENL_MCAST_CAP_NET_ADMIN, ensuring local processes cannot join and receive witness Register messages.

    Linux kernel CIFS witness generic-netlink multicast group (SWN multicast group) Multicast group join capability (GENL_MCAST_CAP_NET_ADMIN) = GENL_MCAST_CAP_NET_ADMIN

Event History

Jul 19, 2026
CVE Published
via MITRE·03:40 PM
Data Sourced
via MITRE·03:40 PM
DescriptionSeverity
Data Sourced
via NVD·04:17 PM
RemedyDescriptionSeverityAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2026-64137?

The severity of CVE-2026-64137 is rated as high with a CVSS score of 7.8.

2

What does CVE-2026-64137 affect?

CVE-2026-64137 affects the Linux kernel, specifically related to the SMB client and CIFS netlink operations.

3

How do I fix CVE-2026-64137?

To fix CVE-2026-64137, it's recommended to update the Linux kernel to the latest version where this vulnerability has been resolved.

4

What type of vulnerability is CVE-2026-64137?

CVE-2026-64137 is a privilege escalation vulnerability that allows unauthorized capabilities for specific netlink operations.

5

Can CVE-2026-64137 be exploited remotely?

Yes, CVE-2026-64137 can be potentially exploited remotely if the affected environment allows SMB operations without proper access controls.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203