CVE-2026-64138: ksmbd: validate SID in parent security descriptor during ACL inheritance
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: validate SID in parent security descriptor during ACL inheritance
Introduce smbvalidatentsdsid() helper to safely validate Owner SID and Group SID inside the NT Security Descriptor (smbntsd) retrieved from the parent directory.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-64138?
CVE-2026-64138 has a severity rating of 8.8, categorized as high.
How do I fix CVE-2026-64138?
To fix CVE-2026-64138, update your Linux kernel to the latest patched version as provided by your distribution.
What systems are affected by CVE-2026-64138?
CVE-2026-64138 affects systems running affected versions of the Linux kernel.
What type of vulnerability is CVE-2026-64138?
CVE-2026-64138 is an access control vulnerability related to the validation of Security Identifiers (SIDs) during Access Control List (ACL) inheritance.
What potential impact does CVE-2026-64138 have?
CVE-2026-64138 can lead to unauthorized access and escalation of privileges due to improper validation of owner and group SIDs.