PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-64395 Linux CVE debrief

A vulnerability in the Linux kernel's ksmbd module allows an attacker to copy file contents into an attacker-readable destination. The vulnerability is due to a lack of proper access control checks when handling the FSCTL_DUPLICATE_EXTENTS_TO_FILE operation. Specifically, the ksmbd module does not require the FILE_READ_DATA access mask on the source handle before performing the copy operation. This could allow an attacker to exploit the vulnerability and gain unauthorized access to sensitive data.

Vendor
Linux
Product
Unknown
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-25
Original CVE updated
2026-09-04
Advisory published
2026-07-25
Advisory updated
2026-09-04

Who should care

Linux kernel maintainers, Linux distribution vendors, and users of Linux-based systems should assess exposure and apply patches or mitigations as needed. Affected operators and security teams must verify that FILE_READ_DATA access mask is required for source handles and implement additional security controls to prevent unauthorized access to sensitive data.

Why it matters

The vulnerability allows an attacker to gain unauthorized access to sensitive data by exploiting the ksmbd module in the Linux kernel. Defenders should assess exposure, apply patches or mitigations, and monitor for suspicious activity.

  • Verify that FILE_READ_DATA access mask is required for source handles
  • Ensure that patches are applied to the Linux kernel
  • Monitor for suspicious activity and implement additional security controls as needed

Technical summary

The Linux kernel's ksmbd module is vulnerable to an unauthorized data access issue due to a lack of proper access control checks when handling the FSCTL_DUPLICATE_EXTENTS_TO_FILE operation. Specifically, the ksmbd module does not require the FILE_READ_DATA access mask on the source handle before performing the copy operation, allowing an attacker to copy file contents into an attacker-readable destination. This requires defenders to assess exposure, apply patches or mitigations, and monitor for suspicious activity.

Defensive priority

High

Recommended defensive actions

  • Review and apply the available patches to the Linux kernel
  • Restrict access to sensitive data and ensure that FILE_READ_DATA access mask is required for source handles
  • Monitor for suspicious activity and implement additional security controls as needed
  • Verify that FILE_READ_DATA access mask is required for source handles
  • Ensure that patches are applied to the Linux kernel
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The vulnerability is described in the CVE record and the NVD vulnerability detail page. The Linux kernel maintainers have provided patches to address this vulnerability. Affected systems require verification of FILE_READ_DATA access mask for source handles and application of patches or mitigations. Defenders should verify exposure, apply patches or mitigations, and monitor for suspicious activity.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-64395 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-64395

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-64395 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-64395

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/2d2ab6983620c2d60ce7db72133984ca3873b929

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/67bdad9cf01b25030e3bf00bbce6c309319d6663

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/a10942af27832c2761d020863a46e79bebe0567d

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/b0d4d5cb846a1ddb7aaab9adfb5986e4540e6e5f

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/cedff600f1642aa982178503552f0d007bc829c8

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/db231af842868268839f9f9619c68cb27830d8be

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.