CVE-2026-68083
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: fix path resolution in ksmbdvfskernpathcreate
The SMB2 open lookup is rooted at the share with LOOKUP_BENEATH, but the
create/mkdir/hardlink sink is not: ksmbdvfskernpathcreate() builds an
absolute path with converttounixname() and resolves it from ATFDCWD
via startcreatingpath(), so a ".." component is walked from the real
filesystem root and escapes the export.
An authenticated client races a missing path component so the rooted open
lookup returns -ENOENT (taking the create branch) while the same component
is present (a directory) when the create walk runs; the create then
resolves ".." out of the share.
Root the create walk at the share like the lookup and rename paths already
are: resolve the parent with vfspathparentlookup(..., LOOKUPBENEATH,
&shareconf->vfspath) and create the final component with
startcreatingnoperm(). converttounix_name() then has no callers and is
removed.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://git.kernel.org/stable/c/1c8951963d8ed357f70f59e0ad4ddce2199d2016, https://git.kernel.org/stable/c/489d1ded01425c0fb33418172c0e4e588467526b, https://git.kernel.org/stable/c/98185b3025beeae92d1fe700d5db26b9ac4bf025, https://git.kernel.org/stable/c/c7c884a1305aa4540eb7942a50bd356b34120e1f, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/68xxx/CVE-2026-68083.json, https://nvd.nist.gov/vuln/detail/CVE-2026-68083, https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git