Junglewise Threat Intelligence

CVE-2026-53010: Linux Kernel ksmbd use-after-free in smb2_open

CVE-2026-53010 · Severity: info · CVSS 0 · Published 2026-06-24

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's ksmbd component, which provides SMB file sharing services. An error in how the system handles re-establishing connections to files could allow a crash or unpredictable behavior. This affects the reliability of file services and could potentially be used to disrupt operations.

Technical details

A use-after-free (UAF) vulnerability exists in the ksmbd component of the Linux kernel within the smb2_open function. The root cause is an early call to ksmbd_put_durable_fd(fp) which prematurely drops the reference count of a durable file descriptor during the reconnect process. If a subsequent error occurs (such as a failure in ksmbd_iov_pin_rsp) or if a background scavenger process accesses the file, the kernel attempts to access properties of the freed 'fp' structure (e.g., fp->create_time). This can be triggered by a remote attacker interacting with SMB2 durable handles. The issue has been resolved by moving the reference release to the end of the function to ensure the object remains valid throughout the execution of smb2_open.

Affected products

  • Linux Linux Kernel 6.6.32 to 6.7, 6.9, 6.18.33, 7.0.10

Timeline

  • 2026-06-24: disclosed
  • 2026-06-24: advisory

References

Related threats