CIFS Network Vulnerability in Linux Kernel by SMB Protocol
CVE-2026-64137
What is CVE-2026-64137?
A security flaw in the Linux kernel allows unprivileged local processes to send critical notifications to the in-kernel witness handler via the CIFS protocol. The vulnerability resides in the lack of capability flags for the CIFS_GENL_CMD_SWN_NOTIFY userspace command, enabling attackers to exploit the system to generate unauthorized notifications such as RESOURCE_CHANGE and CLIENT_MOVE. Additionally, the related multicast group may expose sensitive information like witness registration IDs and authentication credentials, compromising system integrity. The fix mandates CAP_NET_ADMIN privileges for these operations, significantly enhancing security.
Affected Version(s)
Linux fed979a7e082bd9f25f9002c3c4f8740dacd0bc8 < 9cf7eb8919344932f909b2fac76296f7656fda8d
Linux fed979a7e082bd9f25f9002c3c4f8740dacd0bc8 < 9919021a3b7974ae66a5f9915e3a48c10cfd409b
Linux fed979a7e082bd9f25f9002c3c4f8740dacd0bc8 < 969bc6370334a5b4720c5470783295d6484bbc95