PatchSiren cyber security CVE debrief
CVE-2026-52944 Linux CVE debrief
A vulnerability in the Linux kernel's ksmbd module allows clients to bypass file system control (FSCTL) permissions, potentially enabling unauthorized modification of file attributes on shared filesystems. This issue arises from the lack of proper permission checks for the FSCTL_SET_SPARSE operation, affecting Linux kernel versions 5.15 through 7.0.12. Linux administrators and users with shared filesystems should assess exposure and apply patches to prevent unauthorized file attribute modifications.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-24
- Original CVE updated
- 2026-09-14
- Advisory published
- 2026-06-24
- Advisory updated
- 2026-09-14
Who should care
Linux administrators and users with shared filesystems, particularly those using kernel versions 5.15 through 7.0.12, should assess exposure and apply patches to prevent unauthorized file attribute modifications.
Why it matters
The vulnerability in the Linux kernel's ksmbd module allows clients to bypass FSCTL permissions, potentially enabling unauthorized modification of file attributes on shared filesystems. Linux administrators and users with shared filesystems should assess exposure and apply patches to prevent unauthorized file attribute modifications.
- Verify and apply patches for Linux kernel versions 5.15 through 7.0.12
- Assess exposure based on specific deployment contexts and shared filesystem configurations
- Review file system access controls and user permissions
Technical summary
The Linux kernel's ksmbd module did not properly check permissions for the FSCTL_SET_SPARSE operation, allowing clients to modify file sparse attributes without proper authorization. This issue has been addressed with patches available for various kernel versions, including Linux kernel versions 5.15 through 7.0.12. The vulnerability enables unauthorized modification of file attributes on shared filesystems, potentially leading to security breaches if exploited. Defenders should apply patches and review file system access controls to mitigate the vulnerability.
Defensive priority
Apply patches to address the vulnerability, particularly for Linux kernel versions 5.15 through 7.0.12, and assess exposure based on specific deployment contexts.
Recommended defensive actions
- Apply patches to address the vulnerability, particularly for Linux kernel versions 5.15 through 7.0.12
- Assess exposure based on specific deployment contexts and shared filesystem configurations
- Verify file system configurations and access controls
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, including its description, CVSS score, and affected kernel versions. Multiple patch references are available, including official advisories from Linux kernel maintainers and detailed vulnerability assessments from NIST. The vulnerability has been resolved with patches available for various kernel versions. Defenders should verify affected systems, review file system access controls, and apply patches to address the vulnerability.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-52944 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-52944
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-52944 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-52944
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/3127a884525dc8ca4def73254bfcd3ccef0bf812
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/3a9a0a1c38ef90788f5d7c4b29903c8b220f744a
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/aef151bcfa494bfe983669de2726734b534adb73
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/c5ab11263e3c89aa7989afc5374ef7743e092fd0
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/cc57232cae23c0df91b4a59d0f519141ce9b5b02
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/de9eb0b44fa9123170e6245b49638e0e453c10f8
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/ef664475c1bf1a27d45dae6848ca9c9c4d86853f
416baaa9-dc9f-4396-8d5f-8c081fb06d67
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.