Executive brief
A vulnerability in the Linux kernel's SMB server (ksmbd) could allow a remote attacker to cause a system crash. The issue occurs when the server uses certain hardware acceleration chips, like the Qualcomm Crypto Engine, to encrypt or decrypt network traffic. Because the server does not wait for the hardware to finish its task before cleaning up memory, it can lead to a 'use-after-free' error that destabilizes or crashes the operating system.
Technical details
A use-after-free vulnerability exists in ksmbd_crypt_message() within the Linux kernel's ksmbd module. The function fails to properly handle the -EINPROGRESS return code from asynchronous AEAD crypto requests. When an asynchronous hardware engine like the Qualcomm Crypto Engine (QCE) is used, ksmbd incorrectly treats the pending status as an error and immediately frees the request structure while DMA operations are still in flight. This results in a NULL pointer dereference or memory corruption when the DMA completion callback (e.g., qce_skcipher_done) eventually executes. The fix implements the standard crypto_wait_req() pattern to ensure the kernel waits for asynchronous operations to complete before freeing associated memory.
Affected products
- Linux Linux Kernel 5.15 to 6.9.x
Timeline
- 2026-04-06: disclosed: Initial patch authored
- 2026-06-24: advisory: CVE-2026-53046 published
References
- https://git.kernel.org/stable/c/3e298897f41c61450c2e7a4f457e8b2485eb35b3
- https://git.kernel.org/stable/c/57b47231055b431ed0a1a55f33cac32981564405
- https://git.kernel.org/stable/c/7164b3953cefd540e7ebca828c793bc6869cfbc4
- https://git.kernel.org/stable/c/8ef183216feaa24b66b940510d8b68f680eb56e9
- https://git.kernel.org/stable/c/8fcefe840fa8c14ce667768e5b043286ac3bbcbe
- https://git.kernel.org/stable/c/b46aa129fa2807bfe1545fe74d9295d53c51520b
- https://git.kernel.org/stable/c/cc2da381875d4a67026e4c8feb3dba51a2a2d1bc