Executive brief
The Linux kernel's ksmbd SMB server implementation contained a flaw in how it managed session state changes across multiple network connections. The vulnerability could allow unrelated connections to be incorrectly placed in a disconnected or setup state when a user logs off or a session is replaced, potentially disrupting legitimate user sessions or creating service instability.
Technical details
The vulnerability exists in ksmbd_all_conn_set_status(), which incorrectly treats any connection with a transient binding flag set as belonging to a specific session ID, causing logoff or session replacement operations to change the state of unrelated connections to NEED_RECONNECT or NEED_SETUP. The fix scopes session status changes to only connections actually bound to the target session by checking both the connection-local session xarray and the session's permanent channel list. Additionally, session-wide status changes are now serialized under request_lock and protected against overwriting EXITING or RELEASING states, preventing concurrent updates from reviving closing connections.
Affected products
- Linux Linux kernel 5.10 and later (affects ksmbd SMB server subsystem)
Timeline
- 2026-09-17: disclosed: NVD publication of CVE-2026-90154
- 2026-08-13: patched: Upstream fix commit c50e628122aed077695669e25b842e778511a43d authored