PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-64398 Linux CVE debrief

A Linux kernel vulnerability allows an authenticated SMB client to zero file data without proper permissions via the FSCTL_SET_ZERO_DATA ioctl. This issue arises from a missing per-handle access check in the ksmbd implementation. The vulnerability impacts Linux kernel deployments using ksmbd, especially those exposed to authenticated SMB clients. A handle opened with only FILE_WRITE_ATTRIBUTES permissions can zero 4096 bytes of file data it has no FILE_WRITE_DATA right to. This is the unfixed sibling of commit cc57232cae23 (ksmbd: fix FSCTL permission bypass by adding a permission check for FSCTL_SET_SPARSE). Because SET_ZERO_DATA writes data (not an attribute), require FILE_WRITE_

Vendor
Linux
Product
Unknown
CVSS
HIGH 8.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-25
Original CVE updated
2026-09-04
Advisory published
2026-07-25
Advisory updated
2026-09-04

Who should care

Linux kernel maintainers, administrators of Linux-based systems, and security teams responsible for monitoring and patching Linux deployments, especially those using ksmbd and exposed to authenticated SMB clients.

Why it matters

CVE-2026-64398 is a high-severity vulnerability in the Linux kernel's ksmbd implementation that allows authenticated SMB clients to zero file data without proper permissions. This issue requires immediate attention from Linux kernel maintainers, system administrators, and security teams to assess exposure, apply patches, and restrict SMB client access to sensitive systems and data.

  • Potential data loss or corruption due to unauthorized file modifications.
  • Increased risk of data breaches or system compromise through exploitation by malicious SMB clients.
  • Need for urgent assessment and patching of vulnerable Linux kernel deployments.
  • Potential service disruptions due to file system modifications.

Technical summary

The ksmbd implementation in the Linux kernel fails to properly check permissions for the FSCTL_SET_ZERO_DATA ioctl, allowing an authenticated SMB client with a handle opened using FILE_WRITE_ATTRIBUTES permissions to zero file data they are not authorized to modify. This issue is addressed in various Linux kernel patches. The vulnerability was introduced due to a lack of proper permission checks in the ksmbd implementation of the FSCTL_SET_ZERO_DATA ioctl. An authenticated SMB client can exploit this by opening a handle with FILE_WRITE_ATTRIBUTES permissions, which are not sufficient for this operation, allowing them to zero file data they do not have permission to modify. The vulnerability impacts Linux kernel

Defensive priority

High-priority assessment and remediation recommended for Linux kernel deployments using ksmbd, especially those exposed to untrusted or authenticated SMB clients.

Recommended defensive actions

  • Assess Linux kernel deployments for exposure to untrusted or authenticated SMB clients.
  • Verify and apply patches from Linux kernel maintainers.
  • Restrict SMB client access to sensitive data and systems.
  • Monitor for suspicious file modifications.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.

Evidence notes

The vulnerability was introduced due to a lack of proper permission checks in the ksmbd implementation of the FSCTL_SET_ZERO_DATA ioctl. An authenticated SMB client can exploit this by opening a handle with FILE_WRITE_ATTRIBUTES permissions, which are not sufficient for this operation, allowing them to zero file data they do not have permission to modify.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-64398 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-64398

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-64398 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-64398

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/25377f369688dd0bd814dc8965ed26d44238ecaa

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/3072d82461f498c85daea8766e9d8bfbada31605

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/3320ba068198adc144c89d6661b805acce01735b

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/57f2042fd87d7ce8fc3ac8b6c176e554df68b1a7

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/ca53bb17f4e8232cfaece3953d3cef62c559b039

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/deffa929086d7902e30918adf3dd27ccfe9c08b1

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.