Junglewise Threat Intelligence

CVE-2026-53198: Linux Kernel ksmbd use-after-free in SMB2_CANCEL

CVE-2026-53198 · Severity: info · CVSS 0 · Published 2026-06-25

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's ksmbd component, which provides SMB file sharing services. An authenticated user could potentially cause a system crash or instability by sending specific duplicate cancellation requests for file locks. This issue affects the reliability of the file server and could be used to disrupt business operations.

Technical details

A use-after-free (UAF) vulnerability exists in the ksmbd component of the Linux kernel due to improper state management during SMB2_CANCEL operations. When a deferred byte-range lock (SMB2_LOCK) is cancelled, the associated 'file_lock' structure is freed, but the asynchronous work item may remain on the connection's request list without being properly unlinked. If a second SMB2_CANCEL request for the same AsyncId is received before the connection is torn down, the kernel attempts to re-run the cancellation function on the already-freed memory. This can be triggered by an authenticated SMB client and results in a slab use-after-free, typically leading to a kernel panic (DoS). The fix introduces a state check to ensure cancelled work items are not processed a second time.

Affected products

  • Linux Linux Kernel ksmbd module

Timeline

  • 2026-06-01: other: Patch authored
  • 2026-06-25: disclosed: CVE published

References

Related threats