KernelScan.io

CRITICAL Introduced in 5.15

ksmbd ClientGUID Bypass

CVE-2026-74521

CVSS 9.1 / 10.0 NVD

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

KernelScan AI9.6CRITICAL

01

In the Linux kernel, the following vulnerability has been resolved: ksmbd: use memcmp() to compare ClientGUIDs ClientGUID is a fixed-size binary value and can contain embedded NUL bytes. strncmp() stops comparing at the first NUL byte, so different ClientGUID values can incorrectly be treated as equal. Use memcmp() in SMB3 multichannel session binding and FSCTL_VALIDATE_NEGOTIATE_INFO to compare all SMB2_CLIENT_GUID_SIZE bytes.

02

Engine v0.6.0

Risk summary

An unauthenticated network attacker who can reach the ksmbd SMB service can exploit an incorrect binary comparison to bind a new channel onto another client's authenticated SMB3 session, hijacking that session's access to shared files. This bypasses authentication entirely for the hijacked channel, exposing confidentiality and integrity of all data the victim can access. Any device running ksmbd with network exposure is at risk.

Affectedfs/smb/server/smb2pdu.c (ksmbd)

Vulnerability analysis

The ksmbd SMB server compares ClientGUID values using a string comparison function that stops at the first NUL byte, but ClientGUIDs are fixed-size binary values that can contain embedded NULs. When a legitimate client's GUID happens to include a NUL byte, an attacker can craft a different GUID that shares only the prefix before that NUL and still pass the equality check. This affects two security-critical paths: SMB3 multichannel session binding, where a new connection is bound to an existing authenticated session, and the negotiate-info validation ioctl. By passing the check, an unauthenticated network attacker can bind a fresh channel to a victim's session and then issue file operations using the victim's credentials and permissions. The fix replaces the string comparison with a full fixed-length binary comparison so all bytes of the GUID must match. The vulnerable surface is the ksmbd TCP listener (port 445); any network client that can reach the service can attempt the attack without credentials or local access.

03

BranchIntroducedFixed inPatch commit
6.125.156.12.111ba2a5b66f1d4
6.185.156.18.53a386c8304301
7.15.157.1.8d53536329982
mainline5.157.2e8bb506e6ef7