CVE-2026-64137

Source
https://cve.org/CVERecord?id=CVE-2026-64137
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-64137.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-64137
Downstream
Published
2026-07-19T15:40:31.045Z
Modified
2026-07-22T03:31:54.324824884Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
smb: client: require net admin for CIFS SWN netlink
Details

In the Linux kernel, the following vulnerability has been resolved:

smb: client: require net admin for CIFS SWN netlink

CIFSGENLCMDSWNNOTIFY is the userspace witness-notify command. The intended sender is the cifs.witness helper, but the generic-netlink operation currently has no capability flag, so any local process can send RESOURCECHANGE or CLIENTMOVE notifications to the in-kernel witness handler.

The same family exposes CIFSGENLMCGRP_SWN without multicast-group capability flags. Register messages sent to that group include the witness registration id and, for NTLM-authenticated mounts, the username, domain, and password attributes copied from the CIFS session. An unprivileged local process should not be able to join that group and receive those messages.

Require CAPNETADMIN for incoming SWNNOTIFY commands with GENLADMINPERM, and require CAPNETADMIN over the network namespace for joining the SWN multicast group with GENLMCASTCAPNET_ADMIN. The cifs.witness service runs with the privileges needed for both operations.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64137.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
fed979a7e082bd9f25f9002c3c4f8740dacd0bc8
Fixed
9cf7eb8919344932f909b2fac76296f7656fda8d
Fixed
9919021a3b7974ae66a5f9915e3a48c10cfd409b
Fixed
969bc6370334a5b4720c5470783295d6484bbc95
Fixed
a3238b09c58f323e40743ce174cd0ab81b5c09ed
Fixed
a8d17d22db591099519a89f14dd24810daba74c3
Fixed
c2397b93fbb6f44a788fff30f99be2c20cc5e50f
Fixed
d1ebfce2c1d161186a82e77590bf7da2ea1bce91

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-64137.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.210
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.176
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.143
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.92
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.34
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.0.11

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-64137.json"