Junglewise Threat Intelligence

CVE-2025-68817: Linux Kernel ksmbd use-after-free in ksmbd_tree_connect_put

CVE-2025-68817 · Severity: critical · CVSS 9.8 · Published 2026-01-13

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was found in the Linux kernel's SMB server (ksmbd), which is used to share files over a network. Under conditions of high activity, the system may improperly handle memory when a user disconnects, potentially allowing an attacker to crash the system or execute unauthorized commands. This could lead to a total loss of system availability or the exposure of sensitive data stored on the server.

Technical details

A use-after-free (UAF) vulnerability exists in the ksmbd component of the Linux kernel, specifically within the ksmbd_tree_connect_put function. The root cause is a race condition under high concurrency where a tree-connection object (tcon) is freed during a disconnect path while another execution path still holds a reference to it. When the second path later attempts to perform a 'put' or 'write' operation on the freed object, it triggers the UAF. This can be exploited by a remote, unauthenticated attacker (depending on ksmbd configuration) to cause a kernel panic or potentially achieve arbitrary code execution. The fix involves properly utilizing atomic reference counting (atomic_dec_and_test) to ensure the object is only freed when the final reference is released, removing the reliance on unsafe waitqueues for this purpose.

Affected products

  • Linux Linux Kernel 5.15.145 to 5.15.199, 6.1.71 to 6.1.160, 6.6 to 6.6.120, 6.7 to 6.12.64, 6.13 to 6.18.3

Timeline

  • 2026-01-13: advisory: CVE published by NVD
  • 2026-01-02: patched: Initial patch committed to stable tree

References

Related threats