Impact
A use‑after‑free bug in the Linux kernel’s ksmbd SMB server occurs when smb2_tree_connect publishes a new tree connection and a concurrent session logoff frees the object while the handler continues to use it. The flaw is a classic kernel memory corruption. Based on the description, it is inferred that an attacker could potentially crash the kernel or, if the freed memory is subsequently reused, achieve arbitrary code execution with kernel privileges, but the exact impact has not been demonstrated in the advisory.
Affected Systems
All Linux kernel builds that include the ksmbd SMB server and have not yet been patched for CVE‑2026‑89788 are affected. The advisory does not specify exact kernel versions, so any system running ksmbd prior to the commit that fixed smb2_tree_connect should be considered vulnerable.
Risk and Exploitability
The CVSS score of 9.8 indicates a critical severity. The EPSS score is < 1 %, suggesting a low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is network access to the SMB service over TCP 445, where an attacker could initiate a session and trigger a logoff while a tree connection is being established. While the exploitation path requires precise timing, the potential for a kernel panic or user‑level code execution makes this a high‑risk flaw if the conditions are met.
OpenCVE Enrichment