KernelScan.io

CRITICAL Introduced in 6.9

ksmbd DurableReconnect UAF

CVE-2026-53010

CVSS 9.8 / 10.0 NVD

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

KernelScan AI7.1HIGH

01

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in smb2_open during durable reconnect In smb2_open, the call to ksmbd_put_durable_fd(fp) drops the reference to the durable file descriptor early during the durable reconnect process. If an error occurs subsequently (eg, ksmbd_iov_pin_rsp fails) or a scavenger accesses the file, it leads to a use-after-free when accessing fp properties (eg fp->create_time). Move the single put to the end of the function below err_out2 so fp stays valid until smb2_open returns.

02

Engine v0.3.0

Risk summary

A use-after-free vulnerability in the ksmbd kernel SMB server allows an authenticated SMB client to trigger memory corruption during a durable handle reconnect. Because ksmbd_put_durable_fd() drops the reference to the durable file descriptor early while smb2_open() continues to access fp properties, subsequent code paths (including error handling and scavenger activity) can reference freed heap memory. This can leak kernel pointer data from the freed object (C:Low) and enable kernel memory corruption (I:High) or a kernel panic (A:High). The bug is reachable over the network by any authenticated SMB user connecting to a ksmbd share.

Affectedfs/smb/server/smb2pdu.c (ksmbd SMB2 server)

Vulnerability analysis

The vulnerability is a use-after-free in smb2_open() within the ksmbd kernel SMB2 server. During a durable handle reconnect, ksmbd_put_durable_fd(dh_info.fp) was called at multiple early points inside the reconnected block (after smb2_check_durable_oplock, ksmbd_reopen_durable_fd, ksmbd_override_fsids, and after ksmbd_vfs_getattr). After the reference drop, the function continues to use the fp pointer to build responses and handle errors. If an error occurs subsequently (e.g., ksmbd_iov_pin_rsp fails) or a scavenger thread frees the object, the kernel accesses freed fp properties such as fp->create_time and fp->filp, constituting a use-after-free. The fix consolidates the single ksmbd_put_durable_fd call to the end of the function at err_out2, guarded by dh_info.reconnected, ensuring fp remains valid for the entire duration of smb2_open. The attack surface is the SMB2 network protocol: any authenticated client can initiate a durable reconnect request, and the premature put leaves a dangling pointer that is accessed on later success or error paths.

03

BranchIntroducedFixed inPatch commit
6.126.96.12.1104db3dcac84c2
7.06.97.0.1097a0cd55283b
mainline6.97.11baff47b81f9
6.186.96.18.33ce2e164c1c51
6.66.6.326.6.157f0ff7f12398e