{"api_version":"1","generated_at":"2026-08-17T11:26:47+00:00","cve":"CVE-2026-74521","urls":{"html":"https://cve.report/CVE-2026-74521","api":"https://cve.report/api/cve/CVE-2026-74521.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-74521","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-74521"},"summary":{"title":"ksmbd: use memcmp() to compare ClientGUIDs","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: use memcmp() to compare ClientGUIDs\n\nClientGUID is a fixed-size binary value and can contain embedded NUL\nbytes. strncmp() stops comparing at the first NUL byte, so different\nClientGUID values can incorrectly be treated as equal.\n\nUse memcmp() in SMB3 multichannel session binding and\nFSCTL_VALIDATE_NEGOTIATE_INFO to compare all SMB2_CLIENT_GUID_SIZE\nbytes.","state":"PUBLISHED","assigner":"Linux","published_at":"2026-08-15 13:17:57","updated_at":"2026-08-17 06:19:48"},"problem_types":[],"metrics":[{"version":"3.1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","score":"9.1","severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","baseScore":9.1,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"9.1","severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","data":{"baseScore":9.1,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","version":"3.1"}}],"references":[{"url":"https://git.kernel.org/stable/c/d535363299822c5caa543787b21bd5cfa3e41949","name":"https://git.kernel.org/stable/c/d535363299822c5caa543787b21bd5cfa3e41949","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/e8bb506e6ef749ac0336f3e579d8d02396b7d832","name":"https://git.kernel.org/stable/c/e8bb506e6ef749ac0336f3e579d8d02396b7d832","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-74521","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-74521","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 d535363299822c5caa543787b21bd5cfa3e41949 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 e8bb506e6ef749ac0336f3e579d8d02396b7d832 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 5.15","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 5.15 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.1.8 7.1.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"74521","cve":"CVE-2026-74521","epss":"0.001550000","percentile":"0.051990000","score_date":"2026-08-16","updated_at":"2026-08-17 00:01:04"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["fs/smb/server/smb2pdu.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"d535363299822c5caa543787b21bd5cfa3e41949","status":"affected","version":"e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9","versionType":"git"},{"lessThan":"e8bb506e6ef749ac0336f3e579d8d02396b7d832","status":"affected","version":"e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["fs/smb/server/smb2pdu.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"5.15"},{"lessThan":"5.15","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"7.1.*","status":"unaffected","version":"7.1.8","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.2","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.1.8","versionStartIncluding":"5.15","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2","versionStartIncluding":"5.15","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: use memcmp() to compare ClientGUIDs\n\nClientGUID is a fixed-size binary value and can contain embedded NUL\nbytes. strncmp() stops comparing at the first NUL byte, so different\nClientGUID values can incorrectly be treated as equal.\n\nUse memcmp() in SMB3 multichannel session binding and\nFSCTL_VALIDATE_NEGOTIATE_INFO to compare all SMB2_CLIENT_GUID_SIZE\nbytes."}],"metrics":[{"cvssV3_1":{"baseScore":9.1,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","version":"3.1"},"scenarios":[{"lang":"en","value":"AV:N - The bug is in ksmbd's in-kernel SMB server on TCP/445; vulnerable ClientGUID comparisons run while handling remotely supplied SMB2 SESSION_SETUP multichannel binding and SMB2 IOCTL FSCTL_VALIDATE_NEGOTIATE_INFO requests from any network peer.\nAC:L - The attacker controls negotiate ClientGUID bytes (including embedded NULs), can open many TCP connections, brute-force sequential session IDs, and repeatedly attempt binding until strncmp accepts a prefix-colliding GUID without conditions outside attacker control.\nPR:N - Multichannel SESSION_SETUP binding is processed before the attacker authenticates; once a victim SMB2_SESSION_VALID session is targeted, ntlm_authenticate skips password verification on rebind, requiring only network reachability plus session ID and username guessing, not a valid server account.\nUI:N - Exploitation requires no victim interaction such as opening files, mounting shares, or clicking links; the attacker drives negotiate, binding, and IOCTL requests directly against the exposed SMB service.\nS:U - Successful exploitation grants unauthorized use of an existing SMB session and its exported share access within ksmbd's authority, not crossing into another security domain such as host kernel privilege or VM escape.\nC:H - Bypassing ClientGUID verification enables hijacking another client's authenticated SMB3 multichannel session, providing read access to all files, directories, and metadata that victim session may access on server exports.\nI:H - A fraudulently bound channel receives the victim session's channel signing keys and full SMB operation rights, allowing arbitrary create, write, modify, and delete of files and objects permitted to that hijacked session.\nA:N - This is a logical string-comparison flaw causing incorrect authorization decisions, not memory corruption or a crash primitive; exploitation does not inherently panic, oops, or deny kernel or ksmbd availability."}]}],"providerMetadata":{"dateUpdated":"2026-08-17T05:48:13.413Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/d535363299822c5caa543787b21bd5cfa3e41949"},{"url":"https://git.kernel.org/stable/c/e8bb506e6ef749ac0336f3e579d8d02396b7d832"}],"title":"ksmbd: use memcmp() to compare ClientGUIDs","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-74521","datePublished":"2026-08-15T12:27:39.330Z","dateReserved":"2026-08-15T05:44:03.911Z","dateUpdated":"2026-08-17T05:48:13.413Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-08-15 13:17:57","lastModifiedDate":"2026-08-17 06:19:48","problem_types":[],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","baseScore":9.1,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":5.2}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"74521","Ordinal":"1","Title":"ksmbd: use memcmp() to compare ClientGUIDs","CVE":"CVE-2026-74521","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"74521","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: use memcmp() to compare ClientGUIDs\n\nClientGUID is a fixed-size binary value and can contain embedded NUL\nbytes. strncmp() stops comparing at the first NUL byte, so different\nClientGUID values can incorrectly be treated as equal.\n\nUse memcmp() in SMB3 multichannel session binding and\nFSCTL_VALIDATE_NEGOTIATE_INFO to compare all SMB2_CLIENT_GUID_SIZE\nbytes.","Type":"Description","Title":"ksmbd: use memcmp() to compare ClientGUIDs"}]}}}