Executive brief
A vulnerability was found in the Linux kernel's SMB server (ksmbd), which is used to share files over a network. Under conditions of high activity, the system may improperly handle memory when a user disconnects, potentially allowing an attacker to crash the system or execute unauthorized commands. This could lead to a total loss of system availability or the exposure of sensitive data stored on the server.
Technical details
A use-after-free (UAF) vulnerability exists in the ksmbd component of the Linux kernel, specifically within the ksmbd_tree_connect_put function. The root cause is a race condition under high concurrency where a tree-connection object (tcon) is freed during a disconnect path while another execution path still holds a reference to it. When the second path later attempts to perform a 'put' or 'write' operation on the freed object, it triggers the UAF. This can be exploited by a remote, unauthenticated attacker (depending on ksmbd configuration) to cause a kernel panic or potentially achieve arbitrary code execution. The fix involves properly utilizing atomic reference counting (atomic_dec_and_test) to ensure the object is only freed when the final reference is released, removing the reliance on unsafe waitqueues for this purpose.
Affected products
- Linux Linux Kernel 5.15.145 to 5.15.199, 6.1.71 to 6.1.160, 6.6 to 6.6.120, 6.7 to 6.12.64, 6.13 to 6.18.3
Timeline
- 2026-01-13: advisory: CVE published by NVD
- 2026-01-02: patched: Initial patch committed to stable tree
References
- https://git.kernel.org/stable/c/063cbbc6f595ea36ad146e1b7d2af820894beb21
- https://git.kernel.org/stable/c/21a3d01fc6db5129f81edb0ab7cb94fd758bcbea
- https://git.kernel.org/stable/c/446beed646b2e426dd53d27358365f8678e1dd01
- https://git.kernel.org/stable/c/b39a1833cc4a2755b02603eec3a71a85e9dff926
- https://git.kernel.org/stable/c/d092de8a26c952379ded8e6b0bda31d89befac1a
- https://git.kernel.org/stable/c/d64977495e44855f2b28d8ce56107c963a7a50e4