Executive brief
A vulnerability was identified in the Linux kernel's ksmbd component, which provides SMB file sharing services. An error in how the system handles reconnected file handles could lead to a situation where internal file records are not properly cleaned up after a failure. This could potentially lead to system instability or memory management issues in the file server.
Technical details
A vulnerability in ksmbd's smb2_open() logic involves an incorrect file lifetime management during durable reconnects. When ksmbd_reopen_durable_fd() succeeds, it republishes a ksmbd_file into the session's volatile-id table. If a subsequent error occurs in smb2_open(), the cleanup path may call ksmbd_put_durable_fd(), which triggers __ksmbd_close_fd() without session awareness. This results in the file object being freed while its volatile-id entry remains in the session table, creating a dangling reference. The fix ensures that session-aware cleanup (ksmbd_fd_put) is used when a reconnected file is being discarded during an error path.
Affected products
- Linux Linux Kernel 6.18.33, 7.0.10
Timeline
- 2026-07-19: disclosed
- 2026-07-19: advisory