Answer in brief
CVE-2026-64399 records a Critical severity (CVSS 9.8) vulnerability in ksmbd: add permission checks for FSCTL_DUPLICATE_EXTENTS_TO_FILE. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 9.8. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Product | Affected versions | Fixed versions |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | Not reported | Not reported |
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=eb817368f50c1cbe1bd07044124aad7db6330e3a <bf460ad5958d506492de4524a656439da3f99c51 || >=eb817368f50c1cbe1bd07044124aad7db6330e3a <620d133d469295ee7c017ca6aafac335f65c4a5a || >=eb817368f50c1cbe1bd07044124aad7db6330e3a <9b9cf7e65cbeaae1b6636144bacee611cdd7a5d6 || >=eb817368f50c1cbe1bd07044124aad7db6330e3a <baae7b39673ec21073a25e3d14f8feaada01d5df || >=eb817368f50c1cbe1bd07044124aad7db6330e3a <c917e4522d251071dde9871b9142d8ea1186ebfe || >=eb817368f50c1cbe1bd07044124aad7db6330e3a <388e4139db27a9e3612c9d356b826f5b1ff6a9e3 | bf460ad5958d506492de4524a656439da3f99c51, 620d133d469295ee7c017ca6aafac335f65c4a5a, 9b9cf7e65cbeaae1b6636144bacee611cdd7a5d6, baae7b39673ec21073a25e3d14f8feaada01d5df, c917e4522d251071dde9871b9142d8ea1186ebfe, 388e4139db27a9e3612c9d356b826f5b1ff6a9e3 |
| Linux/Linuxgeneric | 5.15 | Not reported |
Published upstream
Jul 25, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 4, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: ksmbd: add permission checks for FSCTL_DUPLICATE_EXTENTS_TO_FILE The FSCTL_DUPLICATE_EXTENTS_TO_FILE arm of smb2_ioctl() overwrites the destination file's data via vfs_clone_file_range() with neither the share-level KSMBD_TREE_CONN_FLAG_WRITABLE check nor a per-handle fp->daccess check that the other write-bearing arms carry. A client can overwrite destination data on a read-only share, or from a handle opened with only FILE_WRITE_ATTRIBUTES (which still yields an FMODE_WRITE filp). FILE_WRITE_ATTRIBUTES-only destination handle overwrote the file's data via the clone. Add both checks, matching the FSCTL_SET_SPARSE permission fix; require FILE_WRITE_DATA since this writes data.
Quoted source text, attributed separately from HOL analysis.