KernelScan.io

HIGH

ksmbd SessionLogoff UAF

CVE-2026-98115

CVSS 8.8 / 10.0 NVD

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

KernelScan AI7.5HIGH

01

In the Linux kernel, the following vulnerability has been resolved: ksmbd: safely drain sessions during logoff SMB3 multichannel allows requests for one session to run on multiple connections. Wait for all channels bound to a session before freeing shared session objects. A deferred byte-range lock remains counted as a running request and only wakes when its file closes. Wake blocked locks during the drain without unpublishing or modifying their file objects. Synchronous CANCEL requests must invoke their cancellation callback to wake pending operations, while CHANGE_NOTIFY completion remains specific to the asynchronous path. Serialize session teardown with channel registration and previous-session cleanup, and use atomic work-state transitions so LOGOFF, CANCEL, and connection teardown invoke cancellation callbacks only once.

02

Engine v0.6.0

Risk summary

An authenticated remote SMB client can trigger a use-after-free in the ksmbd kernel server by exploiting race conditions during session teardown with SMB3 multichannel. The bug allows corruption of shared session objects while requests are still in flight on other connections, potentially leading to arbitrary kernel read/write and denial of service. Any deployment exposing ksmbd on TCP 445 to untrusted or semi-trusted networks is at risk.

Affectedfs/smb/server/smb2pdu.c (ksmbd)

Vulnerability analysis

During SMB3 session logoff or previous-session destruction, the kernel SMB server could free shared session objects while requests were still running on other connections bound to the same session. The original teardown path only waited for the current connection to finish rather than all channels, and deferred file locks remained counted as active requests indefinitely because they only wake when a file closes, stalling the drain. State changes that were not atomic also allowed cancellation callbacks to fire multiple times on objects already being torn down. The fix marks a session as shutting down so teardown and new channel registration cannot overlap, waits for every bound channel to finish before freeing session objects, wakes blocked file locks during the drain without altering their underlying files, and uses atomic state transitions so logoff, cancel, and disconnect operations each invoke cancellation callbacks exactly once. An authenticated remote SMB client can reach this path by establishing a multichannel session and sending a logoff or session-setup with a previous-session identifier while concurrent requests are active on another channel.

03

BranchIntroducedFixed inPatch commit
6.66.6.486.7a7e6df0bb926
6.106.10.76.11d12168084c8c
7.2—7.2.7—
mainline—7.3-rc2—