PatchSiren cyber security CVE debrief
CVE-2026-64395 Linux CVE debrief
A vulnerability in the Linux kernel's ksmbd module allows an attacker to copy file contents into an attacker-readable destination. The vulnerability is due to a lack of proper access control checks when handling the FSCTL_DUPLICATE_EXTENTS_TO_FILE operation. Specifically, the ksmbd module does not require the FILE_READ_DATA access mask on the source handle before performing the copy operation. This could allow an attacker to exploit the vulnerability and gain unauthorized access to sensitive data.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-25
- Original CVE updated
- 2026-09-04
- Advisory published
- 2026-07-25
- Advisory updated
- 2026-09-04
Who should care
Linux kernel maintainers, Linux distribution vendors, and users of Linux-based systems should assess exposure and apply patches or mitigations as needed. Affected operators and security teams must verify that FILE_READ_DATA access mask is required for source handles and implement additional security controls to prevent unauthorized access to sensitive data.
Why it matters
The vulnerability allows an attacker to gain unauthorized access to sensitive data by exploiting the ksmbd module in the Linux kernel. Defenders should assess exposure, apply patches or mitigations, and monitor for suspicious activity.
- Verify that FILE_READ_DATA access mask is required for source handles
- Ensure that patches are applied to the Linux kernel
- Monitor for suspicious activity and implement additional security controls as needed
Technical summary
The Linux kernel's ksmbd module is vulnerable to an unauthorized data access issue due to a lack of proper access control checks when handling the FSCTL_DUPLICATE_EXTENTS_TO_FILE operation. Specifically, the ksmbd module does not require the FILE_READ_DATA access mask on the source handle before performing the copy operation, allowing an attacker to copy file contents into an attacker-readable destination. This requires defenders to assess exposure, apply patches or mitigations, and monitor for suspicious activity.
Defensive priority
High
Recommended defensive actions
- Review and apply the available patches to the Linux kernel
- Restrict access to sensitive data and ensure that FILE_READ_DATA access mask is required for source handles
- Monitor for suspicious activity and implement additional security controls as needed
- Verify that FILE_READ_DATA access mask is required for source handles
- Ensure that patches are applied to the Linux kernel
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The vulnerability is described in the CVE record and the NVD vulnerability detail page. The Linux kernel maintainers have provided patches to address this vulnerability. Affected systems require verification of FILE_READ_DATA access mask for source handles and application of patches or mitigations. Defenders should verify exposure, apply patches or mitigations, and monitor for suspicious activity.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-64395 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-64395
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-64395 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-64395
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/2d2ab6983620c2d60ce7db72133984ca3873b929
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/67bdad9cf01b25030e3bf00bbce6c309319d6663
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/a10942af27832c2761d020863a46e79bebe0567d
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/b0d4d5cb846a1ddb7aaab9adfb5986e4540e6e5f
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/cedff600f1642aa982178503552f0d007bc829c8
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/db231af842868268839f9f9619c68cb27830d8be
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.