{"id":"CVE-2026-64392","summary":"ksmbd: use opener credentials for delete-on-close","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: use opener credentials for delete-on-close\n\nDelete-on-close can be completed by deferred or durable handle teardown,\nwhere no request work is available. Both the base-file unlink and the ADS\nxattr removal consequently run with the ksmbd worker credentials and can\nbypass filesystem permission checks.\n\nRun both operations with the credentials captured in struct file when the\nhandle was opened. This preserves the authenticated user's fsuid, fsgid,\nsupplementary groups and capability restrictions at final close.","modified":"2026-07-28T04:02:54.398968841Z","published":"2026-07-25T08:50:38.634Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64392.json","cna_assigner":"Linux"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/18c59109bb6fb816d5102171666f87cf1e29901d"},{"type":"WEB","url":"https://git.kernel.org/stable/c/4b7059974549d278e30fe70e2a4e421f9839817d"},{"type":"WEB","url":"https://git.kernel.org/stable/c/52e2f21911158ec961cd5aae19c56460db382af0"},{"type":"WEB","url":"https://git.kernel.org/stable/c/e72c15085b6d86f45d224d98aa75b5cace4aaab9"},{"type":"WEB","url":"https://git.kernel.org/stable/c/f08b3f451f12eee4abd8a5981803bc36db84458b"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64392.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-64392"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"f44158485826c076335d6860d35872271a83791d"},{"fixed":"f08b3f451f12eee4abd8a5981803bc36db84458b"},{"fixed":"18c59109bb6fb816d5102171666f87cf1e29901d"},{"fixed":"e72c15085b6d86f45d224d98aa75b5cace4aaab9"},{"fixed":"4b7059974549d278e30fe70e2a4e421f9839817d"},{"fixed":"52e2f21911158ec961cd5aae19c56460db382af0"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64392.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.15.0"},{"fixed":"6.6.145"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.7.0"},{"fixed":"6.12.96"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.18.39"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"7.1.4"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64392.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"}]}