CVE-2026-68083

medium Red Hat
Published: August 10, 2026 (27 days ago)
Last Modified: August 10, 2026
Vendor: Red Hat
Source: REDHAT

Description

A flaw was found in ksmbd, a Linux kernel module that provides an in-kernel SMB server. An authenticated client could exploit a path resolution error, specifically in the `ksmbd_vfs_kern_path_create()` function. This vulnerability allows a client to use ".." components in a path to escape the intended shared directory, potentially leading to unauthorized access to files or directories outside of the configured share.

CWE

CWE-22

Affected Products

Red Hat Enterprise Linux 10Red Hat Enterprise Linux 6Red Hat Enterprise Linux 7Red Hat Enterprise Linux 8Red Hat Enterprise Linux 9

References