Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-64391

In the Linux kernel, the following vulnerability has been resolved: ksmbd: use opener credentials for ADS I/O Alternate data streams are stored as xattrs. Unlike regular file I/O, their read and write paths therefore call VFS xattr helpers which recheck inode permissions and LSM policy using the current task credentials. Run ADS I/O with the credentials captured when the SMB handle was opened.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.005
EPSS Ranking 38.1%
CVSS Severity
CVSS v3 Score 9.8
Products affected by CVE-2026-64391


Contact Us

Shodan ® - All rights reserved