Executive brief
A vulnerability in the Linux kernel's SMB server (ksmbd) could allow a remote attacker to cause a resource leak. ksmbd is used to share files over a network using the SMB protocol. By sending specific requests that trigger a mismatch in file identifiers, an attacker can prevent the system from properly closing file handles, eventually leading to system instability or a denial of service as resources are exhausted.
Technical details
A reference count leak exists in the ksmbd module of the Linux kernel within the parse_durable_handle_context() function. When handling an SMB2_CREATE_DURABLE_HANDLE_REQUEST_V2 request, ksmbd_lookup_fd_cguid() increments the reference count of a file object. If a CreateGuid match is found but the ClientGUID does not match, the code fails to call ksmbd_put_durable_fd() before proceeding to a new open path. This prevents __ksmbd_close_fd() from executing and bypasses the durable scavenger, leading to a long-lived file descriptor leak. An attacker can exploit this over the network to exhaust system resources. The issue has been patched in multiple stable branches of the Linux kernel.
Affected products
- Linux Linux Kernel c8efcc786146 to 407b6e699ba8, f31beef633fb, 06f709d0e531, 8c4a0ef1, 804054d19886
Timeline
- 2026-06-24: advisory: CVE-2026-52996 published by NVD
- 2026-05-23: patched: Fix committed to stable kernel trees
References
- https://git.kernel.org/stable/c/06f709d0e531f3e54d88665dd426be3998a774e6
- https://git.kernel.org/stable/c/407b6e699ba8b45b72cc265eed8a1bc8a7191609
- https://git.kernel.org/stable/c/804054d19886ac6628883d82410f6ee42a818664
- https://git.kernel.org/stable/c/8c4a0ef19c8264c150833131af34541495832cd0
- https://git.kernel.org/stable/c/f31beef633fbf2b5af7805fa187a10bcff1d4b49