SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-64388

HIGH · CVSS 7.8 EPSS 0.12%

Source: NVD + CISA KEV + EPSS · Published 2026-07-25 · Last synced 2026-08-24

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's handling of ownership and group modifications when using SMB3 POSIX Extensions, which could lead to unauthorized access or improper permissions being applied to files. This flaw can be exploited if CIFS_MOUNT_CIFS_ACL or CIFS_MOUNT_MODE_FROM_SID options are not set, potentially compromising data integrity and security. Organizations utilizing Linux systems with SMB3 POSIX Extensions should prioritize patching to mitigate the risk of unauthorized file access.

CVE
CVE-2026-64388
Severity
HIGH
CVSS
7.8
EPSS
0.12%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: smb/client: fix chown/chgrp with SMB3 POSIX Extensions Ownership (chown) and group (chgrp) modifications were being ignored when mounting with SMB3 POSIX Extensions unless CIFS_MOUNT_CIFS_ACL or CIFS_MOUNT_MODE_FROM_SID were also explicitly set. Fix this by checking for posix_extensions in cifs_setattr_nounix() when updating UID and GID, ensuring that id_mode_to_cifs_acl() is called to map and set the ownership/group information on the server.