PatchSiren cyber security CVE debrief
CVE-2026-64398 Linux CVE debrief
A Linux kernel vulnerability allows an authenticated SMB client to zero file data without proper permissions via the FSCTL_SET_ZERO_DATA ioctl. This issue arises from a missing per-handle access check in the ksmbd implementation. The vulnerability impacts Linux kernel deployments using ksmbd, especially those exposed to authenticated SMB clients. A handle opened with only FILE_WRITE_ATTRIBUTES permissions can zero 4096 bytes of file data it has no FILE_WRITE_DATA right to. This is the unfixed sibling of commit cc57232cae23 (ksmbd: fix FSCTL permission bypass by adding a permission check for FSCTL_SET_SPARSE). Because SET_ZERO_DATA writes data (not an attribute), require FILE_WRITE_
- Vendor
- Linux
- Product
- Unknown
- CVSS
- HIGH 8.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-25
- Original CVE updated
- 2026-09-04
- Advisory published
- 2026-07-25
- Advisory updated
- 2026-09-04
Who should care
Linux kernel maintainers, administrators of Linux-based systems, and security teams responsible for monitoring and patching Linux deployments, especially those using ksmbd and exposed to authenticated SMB clients.
Why it matters
CVE-2026-64398 is a high-severity vulnerability in the Linux kernel's ksmbd implementation that allows authenticated SMB clients to zero file data without proper permissions. This issue requires immediate attention from Linux kernel maintainers, system administrators, and security teams to assess exposure, apply patches, and restrict SMB client access to sensitive systems and data.
- Potential data loss or corruption due to unauthorized file modifications.
- Increased risk of data breaches or system compromise through exploitation by malicious SMB clients.
- Need for urgent assessment and patching of vulnerable Linux kernel deployments.
- Potential service disruptions due to file system modifications.
Technical summary
The ksmbd implementation in the Linux kernel fails to properly check permissions for the FSCTL_SET_ZERO_DATA ioctl, allowing an authenticated SMB client with a handle opened using FILE_WRITE_ATTRIBUTES permissions to zero file data they are not authorized to modify. This issue is addressed in various Linux kernel patches. The vulnerability was introduced due to a lack of proper permission checks in the ksmbd implementation of the FSCTL_SET_ZERO_DATA ioctl. An authenticated SMB client can exploit this by opening a handle with FILE_WRITE_ATTRIBUTES permissions, which are not sufficient for this operation, allowing them to zero file data they do not have permission to modify. The vulnerability impacts Linux kernel
Defensive priority
High-priority assessment and remediation recommended for Linux kernel deployments using ksmbd, especially those exposed to untrusted or authenticated SMB clients.
Recommended defensive actions
- Assess Linux kernel deployments for exposure to untrusted or authenticated SMB clients.
- Verify and apply patches from Linux kernel maintainers.
- Restrict SMB client access to sensitive data and systems.
- Monitor for suspicious file modifications.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
The vulnerability was introduced due to a lack of proper permission checks in the ksmbd implementation of the FSCTL_SET_ZERO_DATA ioctl. An authenticated SMB client can exploit this by opening a handle with FILE_WRITE_ATTRIBUTES permissions, which are not sufficient for this operation, allowing them to zero file data they do not have permission to modify.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-64398 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-64398
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-64398 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-64398
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/25377f369688dd0bd814dc8965ed26d44238ecaa
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/3072d82461f498c85daea8766e9d8bfbada31605
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/3320ba068198adc144c89d6661b805acce01735b
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/57f2042fd87d7ce8fc3ac8b6c176e554df68b1a7
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/ca53bb17f4e8232cfaece3953d3cef62c559b039
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/deffa929086d7902e30918adf3dd27ccfe9c08b1
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.