KernelScan.io

CRITICAL Introduced in 5.15

ksmbd AsyncCrypto UAF

CVE-2026-53046

CVSS 9.8 / 10.0 NVD

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

KernelScan AI7.5HIGH

01

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free from async crypto on Qualcomm crypto engine ksmbd_crypt_message() sets a NULL completion callback on AEAD requests and does not handle the -EINPROGRESS return code from async hardware crypto engines like the Qualcomm Crypto Engine (QCE). When QCE returns -EINPROGRESS, ksmbd treats it as an error and immediately frees the request while the hardware DMA operation is still in flight. The DMA completion callback then dereferences freed memory, causing a NULL pointer crash: pc : qce_skcipher_done+0x24/0x174 lr : vchan_complete+0x230/0x27c ... el1h_64_irq+0x68/0x6c ksmbd_free_work_struct+0x20/0x118 [ksmbd] ksmbd_exit_file_cache+0x694/0xa4c [ksmbd] Use the standard crypto_wait_req() pattern with crypto_req_done() as the completion callback, matching the approach used by the SMB client in fs/smb/client/smb2ops.c. This properly handles both synchronous engines (immediate return) and async engines (-EINPROGRESS followed by callback notification).

02

Engine v0.3.0

Risk summary

A use-after-free vulnerability in the ksmbd SMB3 server's AEAD encryption path allows a hardware async crypto engine (e.g., Qualcomm QCE) to dereference freed memory via a DMA completion callback. This can be triggered by an authenticated SMB3 client sending encrypted messages to a server using an async crypto engine, potentially causing a kernel crash or memory corruption. Systems running ksmbd on hardware with async crypto engines (such as Qualcomm SoCs) are at risk of denial of service or possible code execution.

Affectedfs/smb/server/auth.c (ksmbd SMB3 encryption)

Vulnerability analysis

The root cause is that ksmbd_crypt_message() set a NULL completion callback on AEAD requests and did not handle the -EINPROGRESS return code from asynchronous hardware crypto engines. When an async engine like the Qualcomm Crypto Engine (QCE) returns -EINPROGRESS, ksmbd incorrectly treated this as an error and immediately freed the AEAD request structure while the hardware DMA operation was still in flight. When the DMA completed, the hardware's completion callback attempted to dereference the already-freed request memory, causing a NULL pointer dereference/use-after-free crash in interrupt context. The fix replaces the NULL callback with the standard crypto_req_done() completion handler and wraps the encrypt/decrypt call with crypto_wait_req(), which properly blocks until the async operation completes (handling both synchronous immediate returns and asynchronous -EINPROGRESS/-EBUSY flows). This is reachable from the network by an authenticated SMB3 client connecting to a ksmbd server on hardware with an async crypto engine.

03

BranchIntroducedFixed inPatch commit
5.155.155.15.20957b47231055b
7.05.157.0.10b46aa129fa28
mainline5.157.13e298897f41c
6.185.156.18.337164b3953cef
6.125.156.12.918ef183216fea
6.65.156.6.1418fcefe840fa8
6.15.156.1.175cc2da381875d