Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-64138

Опубликовано: 19 июл. 2026
Источник: redhat

Описание

In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate SID in parent security descriptor during ACL inheritance Introduce smb_validate_ntsd_sid() helper to safely validate Owner SID and Group SID inside the NT Security Descriptor (smb_ntsd) retrieved from the parent directory.

A flaw was found in the ksmbd module of the Linux kernel. This vulnerability arises from improper validation of Security Identifiers (SIDs) within the NT Security Descriptor (smb_ntsd) during Access Control List (ACL) inheritance. An attacker could exploit this to bypass intended security restrictions, potentially leading to unauthorized access to resources.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10kernelNot affected
Red Hat Enterprise Linux 6kernelNot affected
Red Hat Enterprise Linux 7kernelNot affected
Red Hat Enterprise Linux 7kernel-rtNot affected
Red Hat Enterprise Linux 8kernelNot affected
Red Hat Enterprise Linux 8kernel-rtNot affected
Red Hat Enterprise Linux 9kernelNot affected
Red Hat Enterprise Linux 9kernel-rtNot affected
Red Hat Hardened Imageserlang27Not affected

Показывать по

Дополнительная информация

Дефект:
CWE-639
https://bugzilla.redhat.com/show_bug.cgi?id=2502495kernel: ksmbd: validate SID in parent security descriptor during ACL inheritance

Связанные уязвимости

CVSS3: 8.8
ubuntu
12 дней назад

In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate SID in parent security descriptor during ACL inheritance Introduce smb_validate_ntsd_sid() helper to safely validate Owner SID and Group SID inside the NT Security Descriptor (smb_ntsd) retrieved from the parent directory.

CVSS3: 8.8
nvd
12 дней назад

In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate SID in parent security descriptor during ACL inheritance Introduce smb_validate_ntsd_sid() helper to safely validate Owner SID and Group SID inside the NT Security Descriptor (smb_ntsd) retrieved from the parent directory.

msrc
10 дней назад

ksmbd: validate SID in parent security descriptor during ACL inheritance

CVSS3: 8.8
debian
12 дней назад

In the Linux kernel, the following vulnerability has been resolved: k ...

CVSS3: 8.8
github
11 дней назад

In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate SID in parent security descriptor during ACL inheritance Introduce smb_validate_ntsd_sid() helper to safely validate Owner SID and Group SID inside the NT Security Descriptor (smb_ntsd) retrieved from the parent directory.