CRITICAL Introduced in 5.15
ksmbd ClientGUID Bypass
CVE-2026-74521
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
KernelScan AI9.6CRITICAL
01Description
In the Linux kernel, the following vulnerability has been resolved: ksmbd: use memcmp() to compare ClientGUIDs ClientGUID is a fixed-size binary value and can contain embedded NUL bytes. strncmp() stops comparing at the first NUL byte, so different ClientGUID values can incorrectly be treated as equal. Use memcmp() in SMB3 multichannel session binding and FSCTL_VALIDATE_NEGOTIATE_INFO to compare all SMB2_CLIENT_GUID_SIZE bytes.
02KernelScan AI Analysis
Risk summary
An unauthenticated network attacker who can reach the ksmbd SMB service can exploit an incorrect binary comparison to bind a new channel onto another client's authenticated SMB3 session, hijacking that session's access to shared files. This bypasses authentication entirely for the hijacked channel, exposing confidentiality and integrity of all data the victim can access. Any device running ksmbd with network exposure is at risk.
Vulnerability analysis
The ksmbd SMB server compares ClientGUID values using a string comparison function that stops at the first NUL byte, but ClientGUIDs are fixed-size binary values that can contain embedded NULs. When a legitimate client's GUID happens to include a NUL byte, an attacker can craft a different GUID that shares only the prefix before that NUL and still pass the equality check. This affects two security-critical paths: SMB3 multichannel session binding, where a new connection is bound to an existing authenticated session, and the negotiate-info validation ioctl. By passing the check, an unauthenticated network attacker can bind a fresh channel to a victim's session and then issue file operations using the victim's credentials and permissions. The fix replaces the string comparison with a full fixed-length binary comparison so all bytes of the GUID must match. The vulnerable surface is the ksmbd TCP listener (port 445); any network client that can reach the service can attempt the attack without credentials or local access.
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| 6.12 | 5.15 | 6.12.111 | ba2a5b66f1d4 |
| 6.18 | 5.15 | 6.18.53 | a386c8304301 |
| 7.1 | 5.15 | 7.1.8 | d53536329982 |
| mainline | 5.15 | 7.2 | e8bb506e6ef7 |