KernelScan.io

HIGH Introduced in 2.6.12

ksmbd ChangeNotify UAF

CVE-2026-90168

CVSS 7.5 / 10.0 KernelScan AI

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

01

In the Linux kernel, the following vulnerability has been resolved: ksmbd: retain connection for pending notify work Deferred CHANGE_NOTIFY work keeps an async message ID after the original request work is released. A durable handle can outlive its connection, so the connection teardown can destroy its async IDA before the handle close releases the pending notify work. Give the synthetic deferred work a connection reference. Release it after the async ID in ksmbd_free_work_struct(). This keeps the async IDA alive until the deferred work is released, even when the original connection has already left the connection list. During server shutdown there is no client to receive a cleanup response. Skip the write and only release the pending work.

02

Engine v0.6.0

Risk summary

An authenticated SMB client can trigger a use-after-free in the ksmbd in-kernel SMB server by exploiting a race between connection teardown and pending CHANGE_NOTIFY work on a durable handle. This can crash the kernel or potentially lead to arbitrary code execution. Any system running ksmbd with network-accessible SMB shares is at risk.

Affectedfs/smb/server/smb2pdu.c (ksmbd)

Vulnerability analysis

When an authenticated client asks the SMB server to watch a directory for changes, the server defers the reply and assigns it a pending message number tied to the connection. The deferred task keeps a pointer to the connection without keeping the connection alive. Because a long-lived file handle can survive after its connection closes, the connection can be torn down and freed while the notification is still pending. Later, when that handle is closed and the deferred task is cleaned up, the server tries to release the pending message number using the already-freed connection, causing a use-after-free. The fix ensures the deferred task keeps the connection alive until the task itself is finished. Any authenticated network client that can open a long-lived handle on an SMB share can trigger this by requesting change notifications and then disconnecting before the handle is closed.

03

BranchIntroducedFixed inPatch commit
7.22.6.127.2.650be5e96c381
mainline2.6.127.3-rc1f495154703cb