Junglewise Threat Intelligence

CVE-2026-52911: Linux Kernel ksmbd session lookup vulnerability in SMB3 multichannel

CVE-2026-52911 · Severity: info · CVSS 0 · Published 2026-06-21

Technologies: Linux. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's SMB server (ksmbd) could allow unauthorized access to user sessions. The ksmbd component provides file-sharing services over a network. Due to a flaw in how connections are tracked, an attacker could potentially interact with sessions they did not create, leading to unauthorized access to shared data or session hijacking.

Technical details

A vulnerability in ksmbd (the Linux kernel SMB server) arises from improper scoping of the 'conn->binding' flag during SMB3 multichannel SESSION_SETUP. When this flag is set, the global session lookup function ksmbd_session_lookup_all() uses a slowpath that can resolve any session by ID, even if that session is not associated with the current connection. This occurs because the flag remains set after the initial call, allowing subsequent requests on the same connection to potentially access other active sessions. The fix tightens the lookup by verifying that the connection is registered in the session's channel list (sess->ksmbd_chann_list) before returning the session object.

Affected products

  • Linux Linux f5a544e3bab7 to e74c00c6af42, f5a544e3bab7 to e3a93ce6e257, f5a544e3bab7 to 1ff46c9915c1, f5a544e3bab7 to 974c1c224e85, f5a544e3bab7 to 2cc8a4db633b, f5a544e3bab7 to 1e2bec062c5c, f5a544e3bab7 to b0da97c034b6

Timeline

  • 2026-06-21: disclosed
  • 2026-06-21: advisory

References