Review reviewHigh

CVE-2026-64137

Linux

In the Linux kernel, the following vulnerability has been resolved: smb: client: require net admin for CIFS SWN netlink CIFS_GENL_CMD_SWN_NOTIFY is the userspace witness-notify command. The intended sender is the cifs.witness helper, but the generic-netlink operation currently has no capability flag, so any local process can send RESOURCE_CHANGE or CLIENT_MOVE notifications to the in-kernel witness handler. The same family exposes CIFS_GENL_MCGRP_SWN without multicast-group capability flags. Register messages sent to that group include the witness registration id and, for NTLM-authenticated...

CVSS
7.8
EPSS
-
- percentile
CISA KEV
Not listed
Published
2026.07.20
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability-
Technical severityCVSS 7.8

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: smb: client: require net admin for CIFS SWN netlink CIFS_GENL_CMD_SWN_NOTIFY is the userspace witness-notify command. The intended sender is the cifs.witness helper, but the generic-netlink operation currently has no capability flag, so any local process can send RESOURCE_CHANGE or CLIENT_MOVE notifications to the in-kernel witness handler. The same family exposes CIFS_GENL_MCGRP_SWN without multicast-group capability flags. Register messages sent to that group include the witness registration id and, for NTLM-authenticated...

Affected product and versions

Product
Linux
Affected versions
>= fed979a7e082bd9f25f9002c3c4f8740dacd0bc8 < 9cf7eb8919344932f909b2fac76296f7656fda8d, >= fed979a7e082bd9f25f9002c3c4f8740dacd0bc8 < 9919021a3b7974ae66a5f9915e3a48c10cfd409b, >= fed979a7e082bd9f25f9002c3c4f8740dacd0bc8 < 969bc6370334a5b4720c5470783295d6484bbc95, >= fed979a7e082bd9f25f9002c3c4f8740dacd0bc8 < a3238b09c58f323e40743ce174cd0ab81b5c09ed, >= fed979a7e082bd9f25f9002c3c4f8740dacd0bc8 < a8d17d22db591099519a89f14dd24810daba74c3, >= fed979a7e082bd9f25f9002c3c4f8740dacd0bc8 < c2397b93fbb6f44a788fff30f99be2c20cc5e50f, >= fed979a7e082bd9f25f9002c3c4f8740dacd0bc8 < d1ebfce2c1d161186a82e77590bf7da2ea1bce91, >= 5.11
Fixed versions
No verified fixed-version field is available yet

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE
Not available
CVE-2026-64137 — Linux | SECUFOCUS NOW