HIGH Introduced in 5.15
ksmbd PreauthSession Leak
CVE-2026-90169
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
01Description
In the Linux kernel, the following vulnerability has been resolved: ksmbd: free preauth sessions on connection teardown SMB3.1.1 multichannel binding preserves the preauthentication hash in a preauth_session between the NTLM negotiate and authenticate requests. The binding NTLM negotiate allocates this object and returns STATUS_MORE_PROCESSING_REQUIRED. If the client disconnects before it sends the authenticate request, neither the authenticate nor error cleanup paths free the object. Release any remaining preauthentication sessions when tearing down the connection. Initialize the list when allocating the connection so that this cleanup is safe regardless of the negotiated dialect.
02KernelScan AI Analysis
Risk summary
A remote attacker can repeatedly trigger preauth session allocation in ksmbd by initiating SMB3.1.1 multichannel binding and disconnecting before completing authentication, causing kernel memory to leak on each attempt. This can lead to denial of service through memory exhaustion on systems running the ksmbd SMB server.
Vulnerability analysis
When an SMB client initiates SMB3.1.1 multichannel binding, the server allocates a preauthentication session object to preserve the preauth hash between the NTLM negotiate and authenticate requests. If the client disconnects after the negotiate response but before sending the authenticate request, the server does not free the object during later authentication or error handling, so it leaks. The fix ensures these leftover sessions are freed when the connection closes, and prepares the session list during connection setup so the cleanup works no matter which SMB version is used. Any network client that can reach the ksmbd TCP port can trigger this leak without authentication.
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| 6.12 | 5.15 | 6.12.110 | b62b1ebb25f0 |
| 6.18 | 5.15 | 6.18.52 | a41a98ee16ae |
| mainline | 5.15 | 7.3-rc1 | 06c7b1d731bc |
| 7.2 | 5.15 | 7.2.6 | 8e2ebc776788 |
| 6.6 | 5.15 | 6.6.157 | effcf48d79d8 |