Junglewise Threat Intelligence

CVE-2026-90171: Linux kernel SMB smbdirect use-after-free in socket destruction

CVE-2026-90171 · Severity: info · CVSS 7 · Published 2026-09-17

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's SMB direct (smbdirect) protocol implementation contains a use-after-free vulnerability in how it releases child socket connections during listener shutdown. An attacker could exploit this to cause kernel crashes or memory corruption on systems running the affected kernel code, potentially leading to denial of service or privilege escalation on vulnerable systems.

Technical details

This is a use-after-free vulnerability (CWE-416) in the Linux kernel's smbdirect subsystem. The vulnerable code releases pending child sockets while holding the listener's handler_mutex lock and before calling rdma_destroy_id(), allowing the listener's _cma_cancel_listens() function to walk freed memory structures. The vulnerability occurs during listener socket shutdown when releasing queued child connections. KASAN detects the slab-use-after-free when the listener's destroy path attempts to access already-freed child id_priv structures. The fix moves child socket release operations outside the handler lock and after the listener's cm_id destruction, preventing the use-after-free condition.

Affected products

  • Linux Linux kernel 7.1.0-next and later (at time of discovery)

Timeline

  • 2026-09-17: disclosed: CVE-2026-90171 published
  • 2026-09-17: patched: Fix committed to Linux kernel (smbdirect socket release ordering corrected)

Related threats