Description
In the Linux kernel, the following vulnerability has been resolved:

smb/server: fix session leak in ksmbd_session_register()

See the procedure below:

smb2_sess_setup
ksmbd_smb2_session_create
__session_create
atomic_set(&sess->refcnt, 2)
hash_add(sessions_table, &sess->hlist, sess->id)
ksmbd_session_register
xa_store(&conn->sessions, sess->id, sess) // fail
ksmbd_user_session_put
atomic_dec(&sess->refcnt) // refcnt is 1, session is not freed

Remove the session from sessions_table and drop its table reference if
xa_store() fails.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Resource Leak leading to potential Denial of Service
Action: Patch
AI Analysis

Impact

In the Linux kernel SMB server implementation, a reference‑counting bug in ksmbd_session_register() caused newly created sessions to remain registered when the underlying store operation failed, preventing the session structure from being freed. The result is a resource leak—accumulating session objects consume kernel memory and keep entries in the session table, which can degrade performance or bring the system to a halt if the leak continues unchecked.

Affected Systems

The vulnerability is present in all Linux kernel builds that include the Linux kernel SMB server (ksmbd) before the fix commit referenced in the advisory. No specific kernel version ranges are listed, so any distribution using an unpatched kernel that contains the vulnerable code path is at risk.

Risk and Exploitability

The EPSS score of less than 1 % indicates a very low but nonzero probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. An attacker would need the ability to initiate SMB sessions that trigger a registration failure; the exploit could be local or remote depending on SMB server exposure. Because the flaw leads to memory/resource exhaustion rather than remote code execution, the overall impact is moderate, and proactive patching is advised to mitigate potential denial‑of‑service risks.

Generated by OpenCVE AI on September 20, 2026 at 01:56 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that includes the patch commit 03a22a003f41b182245e6c71fe565e277cff7094 or later, thereby correcting the reference‑counting logic.
  • If an upgrade is not immediately possible, consider disabling the SMB server (CONFIG_KSMBD) or reducing the maximum number of SMB sessions to limit the potential for resource exhaustion.
  • Continuously monitor kernel memory usage and the size of the SMB session table for unusual growth, and apply additional hardening measures such as limiting SMB client authentication attempts.

Generated by OpenCVE AI on September 20, 2026 at 01:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sun, 20 Sep 2026 02:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-459

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: smb/server: fix session leak in ksmbd_session_register() See the procedure below: smb2_sess_setup ksmbd_smb2_session_create __session_create atomic_set(&sess->refcnt, 2) hash_add(sessions_table, &sess->hlist, sess->id) ksmbd_session_register xa_store(&conn->sessions, sess->id, sess) // fail ksmbd_user_session_put atomic_dec(&sess->refcnt) // refcnt is 1, session is not freed Remove the session from sessions_table and drop its table reference if xa_store() fails.
Title smb/server: fix session leak in ksmbd_session_register()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:06:45.641Z

Reserved: 2026-09-11T19:38:34.789Z

Link: CVE-2026-90152

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:08.207

Modified: 2026-09-17T17:17:08.207

Link: CVE-2026-90152

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T02:00:13Z

Weaknesses