Junglewise Threat Intelligence

CVE-2026-72422: Linux kernel ksmbd use-after-free in SMB2 NEGOTIATE

CVE-2026-72422 · Severity: critical · CVSS 9.8 · Published 2026-08-15

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's ksmbd SMB server component has a race condition that allows concurrent network requests to trigger a use-after-free memory error. An attacker sending multiple SMB2 NEGOTIATE requests on the same connection can cause the server to crash or potentially execute arbitrary code, disrupting file sharing services and potentially compromising systems that rely on SMB for network storage or authentication.

Technical details

The vulnerability is a use-after-free race condition in the ksmbd SMB2 NEGOTIATE handler. The root cause is that conn->preauth_info (a shared connection state structure) is allocated under lock in smb2_handle_negotiate(), but freed and set to NULL on failure. Concurrently, the response send path (smb3_preauth_hash_rsp()) reads conn->preauth_info without holding the connection lock, creating a window where one worker frees the memory while another reads it. Although a NULL check exists in the send path, it races with the free operation, allowing dereferencing of a freed pointer. The fix serializes the read under ksmbd_conn_lock() and re-checks NULL inside the lock, ensuring readers either execute fully before allocation or fully after NULL assignment. Attack vector is network-based, requiring an attacker to send concurrent SMB2 NEGOTIATE requests, with no authentication required. Patch is available in the Linux kernel.

Affected products

  • Linux Linux kernel versions with ksmbd SMB server (approximately 5.10 and later)

Timeline

  • 2026-08-15: disclosed
  • 2026-08-15: patched: Fix resolves the vulnerability by serializing reads under connection lock

Related threats