PT-2026-61454 · Linux+1 · Linux Kernel+1

CVE-2026-64137

·

Published

2026-07-19

·

Updated

2026-09-07

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A flaw exists in the SMB client where the CIFS GENL CMD SWN NOTIFY userspace witness-notify command lacks a capability flag. This allows any local process to send RESOURCE CHANGE or CLIENT MOVE notifications to the in-kernel witness handler. Additionally, the CIFS GENL MCGRP SWN family lacks multicast-group capability flags, enabling unprivileged local processes to join the group and receive sensitive information, including witness registration IDs and, for NTLM-authenticated mounts, the username, domain, and password attributes from the CIFS session.
Recommendations Require CAP NET ADMIN for incoming SWN NOTIFY commands with GENL ADMIN PERM and require CAP NET ADMIN over the network namespace for joining the SWN multicast group with GENL MCAST CAP NET ADMIN.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-64137
USN-8593-1
USN-8603-1
USN-8618-1
USN-8663-1
USN-8664-1
USN-8728-1
USN-8729-1

Affected Products

Linux Kernel
Ubuntu