Executive brief
A vulnerability exists in the Linux kernel's ksmbd module, which provides SMB file sharing services. An attacker can send a specially crafted sequence of network requests that causes the file server to crash. This results in a denial-of-service, preventing all users from accessing shared files until the system is recovered.
Technical details
A vulnerability in ksmbd's smb2_check_user_session() function allows a NULL pointer dereference. The issue arises because the function reuses session information for subsequent operations in a COMPOUND request without verifying that the session state is SMB2_SESSION_VALID. Specifically, a SESSION_SETUP request with an NTLM Type-1 blob creates an 'IN_PROGRESS' session where the user object is still NULL. If this is followed by a related TREE_CONNECT operation in the same compound request, the kernel attempts to dereference the NULL user pointer in ksmbd_ipc_tree_connect_request(), leading to a kernel Oops and a denial-of-service. The fix enforces session validity checks for all non-first operations in a compound branch.
Affected products
- Linux Linux Kernel ksmbd module
Timeline
- 2026-06-27: patched: Patch committed to stable kernel trees.
- 2026-07-19: disclosed: CVE published.
References
- https://git.kernel.org/stable/c/06e1f05a1dbe8bbd054c0927b17fc0a61cc8bef7
- https://git.kernel.org/stable/c/25ff12b82a376ff5c4583102a63d2456a6b9ebb9
- https://git.kernel.org/stable/c/5f983b864d3d473ac533b2f4f44a1bbe5dcbccf4
- https://git.kernel.org/stable/c/609ca17d869d04ba249e32cdcbf13c0b1c66f43c
- https://git.kernel.org/stable/c/7cad3ceaf679c55bc9946685dacafce78ce6b51a
- https://git.kernel.org/stable/c/8f0302fb691537d33ec8f668565257ea9d340ffe
- https://git.kernel.org/stable/c/d2bbbb6c55812220fee5d801c275cc267ea3cbeb