Junglewise Threat Intelligence

CVE-2026-53383: Linux Kernel ksmbd NULL pointer dereference in compound requests

CVE-2026-53383 · Severity: info · CVSS 7.5 · Published 2026-07-19

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability exists in the Linux kernel's ksmbd module, which provides SMB file sharing services. An attacker can send a specially crafted sequence of network requests that causes the file server to crash. This results in a denial-of-service, preventing all users from accessing shared files until the system is recovered.

Technical details

A vulnerability in ksmbd's smb2_check_user_session() function allows a NULL pointer dereference. The issue arises because the function reuses session information for subsequent operations in a COMPOUND request without verifying that the session state is SMB2_SESSION_VALID. Specifically, a SESSION_SETUP request with an NTLM Type-1 blob creates an 'IN_PROGRESS' session where the user object is still NULL. If this is followed by a related TREE_CONNECT operation in the same compound request, the kernel attempts to dereference the NULL user pointer in ksmbd_ipc_tree_connect_request(), leading to a kernel Oops and a denial-of-service. The fix enforces session validity checks for all non-first operations in a compound branch.

Affected products

  • Linux Linux Kernel ksmbd module

Timeline

  • 2026-06-27: patched: Patch committed to stable kernel trees.
  • 2026-07-19: disclosed: CVE published.

References

Related threats