CVE-2026-64379
Published Jul 25, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: smb: client: mask server-provided mode to 07777 in modefromsid When modefromsid is active, parse_dacl() applies the server-provided sub_auth[2] value from the NFS mode SID to cf_mode without masking to 07777. Apply the correct masking, same as in the read path.
Is your site exposed to CVE-2026-64379?
Run a free security scan — no signup, results in seconds.
EPSS — Exploit Prediction
0.0022
Probability of exploitation
0.13%
Percentile rank
EPSS estimates the probability that this vulnerability will be exploited in the wild within the next 30 days. A higher score means more likely to be exploited.
References
Other References
https://git.kernel.org/stable/c/08c600b7e1818539ba5efee4cdb06215c245ca78
https://git.kernel.org/stable/c/5f6f2241034f189c69d4d0b5f8fe24a0c25b0c14
https://git.kernel.org/stable/c/b84e002e0df26bbc6cbd3ca01b8212601fe0ae7d
https://git.kernel.org/stable/c/c6c484a7d5bff6b929a86d7ed5130f29834c6a0d
https://git.kernel.org/stable/c/e3d9c7160d483fc8f9e225aafad8ecbbc43f3151
https://git.kernel.org/stable/c/ee2216dbdf0c677e89bb43e03247dba590ed00ef
https://git.kernel.org/stable/c/f511807feee7cb29b61bdfa86472c7e9e2e5df94
https://git.kernel.org/stable/c/f80add1bfb3425100a325b14f19648e75669a954
Frequently Asked Questions
What is CVE-2026-64379? +
In the Linux kernel, the following vulnerability has been resolved:
smb: client: mask server-provided mode to 07777 in modefromsid
When modefromsid is active, parse_dacl() applies the server-provided
sub_auth[2] value from the NFS mode SID to cf_mode without masking to
07777. Apply the correct masking, same as in the read path.
How do I check if I'm vulnerable to CVE-2026-64379? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.