Junglewise Threat Intelligence

CVE-2026-90154: Linux kernel ksmbd session state change race condition

CVE-2026-90154 · Severity: info · Published 2026-09-17

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's ksmbd SMB server implementation contained a flaw in how it managed session state changes across multiple network connections. The vulnerability could allow unrelated connections to be incorrectly placed in a disconnected or setup state when a user logs off or a session is replaced, potentially disrupting legitimate user sessions or creating service instability.

Technical details

The vulnerability exists in ksmbd_all_conn_set_status(), which incorrectly treats any connection with a transient binding flag set as belonging to a specific session ID, causing logoff or session replacement operations to change the state of unrelated connections to NEED_RECONNECT or NEED_SETUP. The fix scopes session status changes to only connections actually bound to the target session by checking both the connection-local session xarray and the session's permanent channel list. Additionally, session-wide status changes are now serialized under request_lock and protected against overwriting EXITING or RELEASING states, preventing concurrent updates from reviving closing connections.

Affected products

  • Linux Linux kernel 5.10 and later (affects ksmbd SMB server subsystem)

Timeline

  • 2026-09-17: disclosed: NVD publication of CVE-2026-90154
  • 2026-08-13: patched: Upstream fix commit c50e628122aed077695669e25b842e778511a43d authored

References

Related threats