Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-68457— ksmbd: use opener credentials for FSCTL mutations

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Linux kernel是美国Linux基金会开源的一个操作系统内核。 Linux kernel 6.1.178之前版本、6.6.145之前版本、6.12.97之前版本、6.18.40之前版本和7.1.5之前版本存在安全漏洞,该漏洞源于ksmbd在处理FSCTL的SET_SPARSE、SET_ZERO_DATA和SET_COMPRESSION操作时使用当前工作线程凭据而非打开句柄时的凭据,可能导致权限提升或绕过访问控制。

CVSS 9.1 · Critical EPSS 0.48% · P39

Affected Version Matrix 14

VendorProduct Version RangeStatus
Linux Linux e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9< a8c18434e1f0d9f7989170bdb0490c0160baf065 affected
e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9< 1e112c47ec5dd1942e2d4ca6e8e9b712238e20c2 affected
e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9< fb1cae6302d58414ddf029e3f642711bd30243f7 affected
e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9< e205f3e7e8c31a47cd11efb6cf663a527177e432 affected
e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9< cfb2c6f71d61ed807c9d7a7af331d406f1f31877 affected
e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9< c6394bcaf254c5baf9aff43376020be5db6d3316 affected
5.15 affected
< 5.15 unaffected
… +6 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-68457

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
ksmbd: use opener credentials for FSCTL mutations
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: ksmbd: use opener credentials for FSCTL mutations SET_SPARSE, SET_ZERO_DATA and SET_COMPRESSION operate on an open SMB handle but call VFS xattr, fallocate or fileattr helpers with the current ksmbd worker credentials. Those helpers can revalidate inode permissions, ownership and LSM policy independently of the SMB handle access mask. Run each operation with the credentials captured in the target file when the handle was opened. Keep credential handling local to these single-file FSCTLs rather than applying session credentials to the complete IOCTL handler, which also contains handle-less and multi-handle operations.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会开源的一个操作系统内核。 Linux kernel 6.1.178之前版本、6.6.145之前版本、6.12.97之前版本、6.18.40之前版本和7.1.5之前版本存在安全漏洞,该漏洞源于ksmbd在处理FSCTL的SET_SPARSE、SET_ZERO_DATA和SET_COMPRESSION操作时使用当前工作线程凭据而非打开句柄时的凭据,可能导致权限提升或绕过访问控制。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 ~ a8c18434e1f0d9f7989170bdb0490c0160baf065 -
Linux Linux 5.15 -

II. Public POCs for CVE-2026-68457

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-68457

登录查看更多情报信息。

Patches & Fixes for CVE-2026-68457 (6)

Same Patch Batch · Linux · 2026-08-15 · 845 CVEs total

CVE-2026-72421 10.0 CRITICAL ipv4: fib: Don't ignore error route in local/main tables.
CVE-2026-74475 10.0 CRITICAL vxlan: use neigh_ha_snapshot() in route_shortcircuit()
CVE-2026-74279 10.0 CRITICAL crypto: cavium/cpt - fix DMA cleanup using wrong loop index
CVE-2026-74280 10.0 CRITICAL crypto: marvell/octeontx - fix DMA cleanup using wrong loop index
CVE-2026-74309 10.0 CRITICAL vdpa/octeon_ep: fix IRQ-to-ring mapping in interrupt handler
CVE-2026-72408 10.0 CRITICAL geneve: gate GRO hint in geneve_gro_complete() on gs->gro_hint
CVE-2026-72407 10.0 CRITICAL geneve: validate inner network offset in geneve_gro_complete()
CVE-2026-72493 9.9 CRITICAL net: serialize netif_running() check in enqueue_to_backlog()
CVE-2026-72206 9.8 CRITICAL ntfs: validate index block header more strictly
CVE-2026-72317 9.8 CRITICAL SUNRPC: pin upper rpc_clnt across the TLS connect_worker
CVE-2026-72208 9.8 CRITICAL ntfs: add bounds check before accessing EA entries
CVE-2026-72065 9.8 CRITICAL net: mana: Validate the packet length reported by the NIC
CVE-2026-72064 9.8 CRITICAL net: mana: Sync page pool RX frags for CPU
CVE-2026-74427 9.8 CRITICAL afs: Fix netns teardown to cancel the preallocation charger
CVE-2026-72137 9.8 CRITICAL xfrm: nat_keepalive: avoid double free on send error
CVE-2026-74428 9.8 CRITICAL rxrpc: Fix double unlock in rxrpc_recvmsg()
CVE-2026-72429 9.8 CRITICAL ipv6: ioam: fix type confusion of dst_entry
CVE-2026-72139 9.8 CRITICAL tcp: defer md5sig_info kfree past RCU grace period in tcp_connect
CVE-2026-74545 9.8 CRITICAL rtase: fix double free of multi-frag skb on DMA map failure
CVE-2026-72046 9.8 CRITICAL gve: fix header buffer corruption with header-split and HW-GRO

Showing top 20 of 845 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-68457

No comments yet


Leave a comment