Executive brief
ksmbd is a Linux kernel SMB server implementation that handles file sharing and authentication. A flaw in NTLM authentication processing allows an authenticated attacker to destroy another user's session without valid credentials, causing service disruption and potential session hijacking. The vulnerability occurs because session termination happens before credential validation completes.
Technical details
The vulnerability is a use-before-check logic error in the ntlm_authenticate() function in fs/smb/server/smb2pdu.c. The code was calling destroy_previous_session() using a user pointer resolved from the client-supplied NTLM blob username field before the NTLMv2 response was validated. An authenticated attacker can craft an NTLM authentication request with the blob username matching a victim account and the PreviousSessionId field set to the victim's session ID; destroy_previous_session() would destroy the victim's session even though the authentication request would subsequently be rejected with -EPERM by ksmbd_decode_ntlmssp_auth_blob(). The fix moves the destroy_previous_session() call and prev_id assignment to after ksmbd_decode_ntlmssp_auth_blob() returns success, ensuring only authenticated sessions trigger the destruction logic. Network access and valid credentials are required; patches are available in the Linux kernel stable tree.
Affected products
- Linux Linux kernel versions with ksmbd SMB server implementation
Timeline
- 2026-08-10: disclosed
- 2026-08-03: patched