ksmbd: fix path resolution in ksmbd_vfs_kern_path_create
Summary
| CVE | CVE-2026-68083 |
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-10 12:17:20 UTC |
| Updated | 2026-08-10 12:17:20 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved:
ksmbd: fix path resolution in ksmbd_vfs_kern_path_create
The SMB2 open lookup is rooted at the share with LOOKUP_BENEATH, but the
create/mkdir/hardlink sink is not: ksmbd_vfs_kern_path_create() builds an
absolute path with convert_to_unix_name() and resolves it from AT_FDCWD
via start_creating_path(), so a ".." component is walked from the real
filesystem root and escapes the export.
An authenticated client races a missing path component so the rooted open
lookup returns -ENOENT (taking the create branch) while the same component
is present (a directory) when the create walk runs; the create then
resolves ".." out of the share.
Root the create walk at the share like the lookup and rename paths already
are: resolve the parent with vfs_path_parent_lookup(..., LOOKUP_BENEATH,
&share_conf->vfs_path) and create the final component with
start_creating_noperm(). convert_to_unix_name() then has no callers and is
removed. |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|
| CNA |
Linux |
Linux |
affected 265fd1991c1db85fbabaad4946ca0e63e2ae688d 489d1ded01425c0fb33418172c0e4e588467526b git |
Not specified |
| CNA |
Linux |
Linux |
affected 265fd1991c1db85fbabaad4946ca0e63e2ae688d c7c884a1305aa4540eb7942a50bd356b34120e1f git |
Not specified |
| CNA |
Linux |
Linux |
affected 265fd1991c1db85fbabaad4946ca0e63e2ae688d 98185b3025beeae92d1fe700d5db26b9ac4bf025 git |
Not specified |
| CNA |
Linux |
Linux |
affected 265fd1991c1db85fbabaad4946ca0e63e2ae688d 1c8951963d8ed357f70f59e0ad4ddce2199d2016 git |
Not specified |
| CNA |
Linux |
Linux |
affected 5.15 |
Not specified |
| CNA |
Linux |
Linux |
unaffected 5.15 semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.12.97 6.12.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.18.40 6.18.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.1.5 7.1.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.2-rc1 * original_commit_for_fix |
Not specified |
References
| Reference | Source | Link | Tags |
|---|
| git.kernel.org/stable/c/1c8951963d8ed357f70f59e0ad4ddce2199d2016 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/98185b3025beeae92d1fe700d5db26b9ac4bf025 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/489d1ded01425c0fb33418172c0e4e588467526b |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/c7c884a1305aa4540eb7942a50bd356b34120e1f |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.