Description
In the Linux kernel, the following vulnerability has been resolved:

ksmbd: scope session state changes to bound connections

ksmbd_all_conn_set_status() treats every connection whose transient
binding flag is set as belonging to the target SessionId. A logoff or
session replacement can consequently move an unrelated connection to
NEED_RECONNECT or NEED_SETUP.

Pass the target session itself and select connections using either the
connection-local session xarray or the session's permanent channel list.
Use the same association test while waiting for requests to drain.

Serialize session-wide status changes under request_lock and do not
overwrite EXITING or RELEASING. Protect the shutdown transition with the
same lock so a concurrent session update cannot revive a closing
connection.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via session mismanagement
Action: Immediate Patch
AI Analysis

Impact

The ksmbd_all_conn_set_status function incorrectly treats every connection whose transient binding flag is set as belonging to the target SessionId. A logoff or session replacement can therefore move unrelated connections into NEED_RECONNECT or NEED_SETUP, causing unintended state changes and potentially disrupting active SMB connections. This flaw exposes the system to availability issues, as legitimate sessions may be forced to reconnect or reset without user intervention.

Affected Systems

The vulnerability affects all Linux kernel installations that include the ksmbd subsystem; no specific kernel versions were supplied, so every kernel with ksmbd is potentially impacted until a patch is deployed.

Risk and Exploitability

The EPSS score is below 1% and the vulnerability is not listed in CISA's KEV catalog, indicating a very low likelihood of exploitation under current conditions. The likely attack vector is local or privileged access, based on the description. However, the flaw could be leveraged in scenarios with local or privileged access to force connections to fail, thereby degrading service availability. No direct remote code execution capability is reported. The absence of a publicly disclosed exploit and the low EPSS suggest that the risk is moderate if the affected service is exposed. Organizations should assume a moderate risk and plan remediation accordingly.

Generated by OpenCVE AI on September 20, 2026 at 02:50 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to the latest stable release that contains the ksmbd session state fix.
  • If the kernel upgrade cannot be performed immediately, temporarily disable the ksmbd service to prevent inadvertent session state changes until a patch is applied.
  • Monitor SMB connections for unexpected NEED_RECONNECT or NEED_SETUP status changes and remediate any abnormal sessions promptly.

Generated by OpenCVE AI on September 20, 2026 at 02:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 03:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285
CWE-682

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: ksmbd: scope session state changes to bound connections ksmbd_all_conn_set_status() treats every connection whose transient binding flag is set as belonging to the target SessionId. A logoff or session replacement can consequently move an unrelated connection to NEED_RECONNECT or NEED_SETUP. Pass the target session itself and select connections using either the connection-local session xarray or the session's permanent channel list. Use the same association test while waiting for requests to drain. Serialize session-wide status changes under request_lock and do not overwrite EXITING or RELEASING. Protect the shutdown transition with the same lock so a concurrent session update cannot revive a closing connection.
Title ksmbd: scope session state changes to bound connections
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:06:47.046Z

Reserved: 2026-09-11T19:38:34.789Z

Link: CVE-2026-90154

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:08.500

Modified: 2026-09-17T17:17:08.500

Link: CVE-2026-90154

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T03:00:11Z

Weaknesses