CVE-2026-64138

Source
https://cve.org/CVERecord?id=CVE-2026-64138
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-64138.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-64138
Downstream
Published
2026-07-19T15:40:31.760Z
Modified
2026-07-22T03:31:45.714157518Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
ksmbd: validate SID in parent security descriptor during ACL inheritance
Details

In the Linux kernel, the following vulnerability has been resolved:

ksmbd: validate SID in parent security descriptor during ACL inheritance

Introduce smbvalidatentsdsid() helper to safely validate Owner SID and Group SID inside the NT Security Descriptor (smbntsd) retrieved from the parent directory.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64138.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9
Fixed
f0e5c9c663badc9982e6941322eef1cb17de0f11
Fixed
18d8db24b0a5b7be4829238dd4022236df02d421
Fixed
1c9d0646a9959752f11ca1080dc1ff26bd1756cb
Fixed
69f030cf95488ae1186c72ac8c66fd279664ea7f

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-64138.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.15.0
Fixed
6.12.92
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.34
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.0.11

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-64138.json"