KernelScan.io

HIGH

smb SessionRegister Leak

CVE-2026-90152

CVSS 7.5 / 10.0 KernelScan AI

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

01

In the Linux kernel, the following vulnerability has been resolved: smb/server: fix session leak in ksmbd_session_register() See the procedure below: smb2_sess_setup ksmbd_smb2_session_create __session_create atomic_set(&sess->refcnt, 2) hash_add(sessions_table, &sess->hlist, sess->id) ksmbd_session_register xa_store(&conn->sessions, sess->id, sess) // fail ksmbd_user_session_put atomic_dec(&sess->refcnt) // refcnt is 1, session is not freed Remove the session from sessions_table and drop its table reference if xa_store() fails.

02

Engine v0.6.0

Risk summary

A remote, unauthenticated attacker can send crafted SMB2 session setup requests to a ksmbd server, causing session objects to leak in kernel memory when an internal allocation fails. Repeated exploitation exhausts kernel memory, leading to system-wide denial of service. Any device running ksmbd exposed to a network is at risk.

Affectedfs/smb/server/mgmt/user_session.c (ksmbd)

Vulnerability analysis

When an SMB2 session setup request is processed, the kernel SMB server creates a session object, registers it in a global hash table with an elevated reference count, and then attempts to store it in the connection's session array. If that store operation fails — typically under memory pressure — the error path returns without removing the session from the global table or dropping the table's reference. The caller drops its own reference, but the lingering table reference keeps the session alive forever, leaking kernel memory. An unauthenticated network attacker can repeatedly send session setup requests to accumulate leaked sessions and drive the system to OOM. The fix adds cleanup on failure: the session is removed from the global table and the table reference is dropped, allowing the object to be freed.

03

BranchIntroducedFixed inPatch commit
5.155.15.1455.1603a22a003f41
6.16.1.296.2b967a595fb73
6.36.3.26.499b25b046e47
6.12—6.12.110—
6.18—6.18.52—
7.2—7.2.6—
mainline—7.3-rc1—
6.26.2.166.355c677619084