CVE-2026-64400 — Linux: In the Linux kernel, the following vulnerability has been resolved: ksmbd: prevent path traversal
In the Linux kernel, the following vulnerability has been resolved: ksmbd: prevent path traversal bypass by restricting caseless retry ksmbd_vfs_path_lookup() enforces LOOKUP_BENEATH to restrict path resolution within the share root. When a crafted path attempts to escape the share boundary using parent-directory components ('..'), vfs_path_parent_lookup() detects this and immediately fails, returning -EXDEV. However, a bug exists in __ksmbd_vfs_kern_path() under caseless CVSSv3.1 8.6 (HIGH) · EPSS 17th percentile