CVE-2026-64398 Details
Description
In the Linux kernel, the following vulnerability has been resolved: ksmbd: add a permission check for FSCTL_SET_ZERO_DATA FSCTL_SET_ZERO_DATA in smb2_ioctl() destroys file data via ksmbd_vfs_zero_data() -> vfs_fallocate(PUNCH_HOLE/ZERO_RANGE) after checking only the share-level KSMBD_TREE_CONN_FLAG_WRITABLE, with no per-handle access check. A handle opened with only FILE_WRITE_ATTRIBUTES still yields an FMODE_WRITE filp (FILE_WRITE_ATTRIBUTES is part of FILE_WRITE_DESIRE_ACCESS_LE, so smb2_create_open_flags() opens it O_WRONLY), so the vfs_fallocate FMODE_WRITE check does not stop it; only the missing fp->daccess gate would. Reproduced on mainline 7.1-rc7 with KASAN by an authenticated SMB client: a FILE_WRITE_ATTRIBUTES-only handle zeroed 4096 bytes of file data it had no FILE_WRITE_DATA right to (6/6; a FILE_READ_DATA-only handle was correctly denied). This is the unfixed sibling of commit cc57232cae23 ("ksmbd: fix FSCTL permission bypass by adding a permission check for FSCTL_SET_SPARSE"). Because SET_ZERO_DATA writes data (not an attribute), require FILE_WRITE_DATA.
A vulnerability in the Linux kernel's KSMBD SMB server implementation allows for unauthorized data modification. The issue arises in the handling of the FSCTL_SET_ZERO_DATA command within the smb2_ioctl function. This command, which is intended to zero out file data, is executed without proper permission checks on a per-handle basis. Instead, it only verifies if the share-level KSMBD_TREE_CONN_FLAG_WRITABLE is set. As a result, a handle opened with the FILE_WRITE_ATTRIBUTES permission can inadvertently gain write access to file data, bypassing the intended restrictions. This vulnerability was reproduced on Linux kernel version 7.1-rc7, using the Kernel Address Sanitizer (KASAN) to simulate an authenticated SMB client. The client was able to zero out 4096 bytes of data without the necessary FILE_WRITE_DATA rights, while a handle with only FILE_READ_DATA access was correctly denied.
Users should ensure that their Linux kernel version is updated to a patched release where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/25377f369688dd0bd814dc8965ed26d44238ecaa | kernel.org | Patch |
| https://git.kernel.org/stable/c/3072d82461f498c85daea8766e9d8bfbada31605 | kernel.org | Patch |
| https://git.kernel.org/stable/c/3320ba068198adc144c89d6661b805acce01735b | kernel.org | Patch |
| https://git.kernel.org/stable/c/57f2042fd87d7ce8fc3ac8b6c176e554df68b1a7 | kernel.org | Patch |
| https://git.kernel.org/stable/c/ca53bb17f4e8232cfaece3953d3cef62c559b039 | kernel.org | Patch |
| https://git.kernel.org/stable/c/deffa929086d7902e30918adf3dd27ccfe9c08b1 | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 5.15, < 6.1.178 >= 6.2, < 6.6.145 >= 6.7, < 6.12.96 >= 6.13, < 6.18.39 >= 6.19, < 7.1.4 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 4, 2026 | Initial Analysis | [email protected] |
| Aug 17, 2026 | CVE Modified | kernel.org |
| Jul 27, 2026 | CVE Modified | kernel.org |
| Jul 25, 2026 | New CVE Received | kernel.org |