Impact
In the Linux kernel SMB server implementation, a reference‑counting bug in ksmbd_session_register() caused newly created sessions to remain registered when the underlying store operation failed, preventing the session structure from being freed. The result is a resource leak—accumulating session objects consume kernel memory and keep entries in the session table, which can degrade performance or bring the system to a halt if the leak continues unchecked.
Affected Systems
The vulnerability is present in all Linux kernel builds that include the Linux kernel SMB server (ksmbd) before the fix commit referenced in the advisory. No specific kernel version ranges are listed, so any distribution using an unpatched kernel that contains the vulnerable code path is at risk.
Risk and Exploitability
The EPSS score of less than 1 % indicates a very low but nonzero probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. An attacker would need the ability to initiate SMB sessions that trigger a registration failure; the exploit could be local or remote depending on SMB server exposure. Because the flaw leads to memory/resource exhaustion rather than remote code execution, the overall impact is moderate, and proactive patching is advised to mitigate potential denial‑of‑service risks.
OpenCVE Enrichment
Debian DLA
Debian DSA