PT-2026-64600 · Linux+2 · Linux Kernel+2

CVE-2026-64379

·

Published

2026-07-25

·

Updated

2026-09-07

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the SMB client where the parse dacl() function fails to mask the server-provided sub auth[2] value from the NFS mode SID to 07777 when modefromsid is active. This value is applied directly to cf mode without the necessary masking used in the read path.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

ALSA-2026:57251
ALSA-2026:57252
ALSA-2026:57253
ALSA-2026:57254
AZL-93647
CVE-2026-64379
ECHO-182F-D32E-84D2
OESA-2026-3317
OPENSUSE-SU-2026:11476-1
USN-8726-1
USN-8727-1
USN-8728-1

Affected Products

Linux Kernel
Rocky Linux
Ubuntu