PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-52944 Linux CVE debrief

A vulnerability in the Linux kernel's ksmbd module allows clients to bypass file system control (FSCTL) permissions, potentially enabling unauthorized modification of file attributes on shared filesystems. This issue arises from the lack of proper permission checks for the FSCTL_SET_SPARSE operation, affecting Linux kernel versions 5.15 through 7.0.12. Linux administrators and users with shared filesystems should assess exposure and apply patches to prevent unauthorized file attribute modifications.

Vendor
Linux
Product
Unknown
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-24
Original CVE updated
2026-09-14
Advisory published
2026-06-24
Advisory updated
2026-09-14

Who should care

Linux administrators and users with shared filesystems, particularly those using kernel versions 5.15 through 7.0.12, should assess exposure and apply patches to prevent unauthorized file attribute modifications.

Why it matters

The vulnerability in the Linux kernel's ksmbd module allows clients to bypass FSCTL permissions, potentially enabling unauthorized modification of file attributes on shared filesystems. Linux administrators and users with shared filesystems should assess exposure and apply patches to prevent unauthorized file attribute modifications.

  • Verify and apply patches for Linux kernel versions 5.15 through 7.0.12
  • Assess exposure based on specific deployment contexts and shared filesystem configurations
  • Review file system access controls and user permissions

Technical summary

The Linux kernel's ksmbd module did not properly check permissions for the FSCTL_SET_SPARSE operation, allowing clients to modify file sparse attributes without proper authorization. This issue has been addressed with patches available for various kernel versions, including Linux kernel versions 5.15 through 7.0.12. The vulnerability enables unauthorized modification of file attributes on shared filesystems, potentially leading to security breaches if exploited. Defenders should apply patches and review file system access controls to mitigate the vulnerability.

Defensive priority

Apply patches to address the vulnerability, particularly for Linux kernel versions 5.15 through 7.0.12, and assess exposure based on specific deployment contexts.

Recommended defensive actions

  • Apply patches to address the vulnerability, particularly for Linux kernel versions 5.15 through 7.0.12
  • Assess exposure based on specific deployment contexts and shared filesystem configurations
  • Verify file system configurations and access controls
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, including its description, CVSS score, and affected kernel versions. Multiple patch references are available, including official advisories from Linux kernel maintainers and detailed vulnerability assessments from NIST. The vulnerability has been resolved with patches available for various kernel versions. Defenders should verify affected systems, review file system access controls, and apply patches to address the vulnerability.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-52944 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-52944

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-52944 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-52944

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/3127a884525dc8ca4def73254bfcd3ccef0bf812

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/3a9a0a1c38ef90788f5d7c4b29903c8b220f744a

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/aef151bcfa494bfe983669de2726734b534adb73

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/c5ab11263e3c89aa7989afc5374ef7743e092fd0

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/cc57232cae23c0df91b4a59d0f519141ce9b5b02

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/de9eb0b44fa9123170e6245b49638e0e453c10f8

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/ef664475c1bf1a27d45dae6848ca9c9c4d86853f

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.