Description
In the Linux kernel, the following vulnerability has been resolved:

smb/server: call ksmbd_proc_cleanup() on module init failure

When a later initializer fails, the unwind chain releases resources
created after procfs and then jumps directly to class_unregister().
Returning an error from module_init() leaves the proc tree and its
per-CPU counters allocated.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Potential resource exhaustion via uncleaned procfs and per-CPU counters left allocated after a kernel module fails to initialize
Action: Update Kernel
AI Analysis

Impact

The vulnerability arises when a Linux kernel module initialization fails after creating procfs entries and per‑CPU counters. The failure path incorrectly releases only post‑procfs resources and then aborts by calling class_unregister(), leaving the proc tree and its counters in an allocated state. This leak can consume kernel memory or expose dangling kernel pointers, potentially causing a denial‑of‑service or allowing further exploitation by a privileged attacker.

Affected Systems

All Linux kernel builds are affected, as the issue exists in the core smb/server subsystem. No specific kernel versions are enumerated in the CVE data; any build that includes this code path is potentially impacted.

Risk and Exploitability

The EPSS score is reported as less than 1 %, indicating a very low probability of exploitation in the wild. The vulnerability requires a kernel module init failure, which typically demands elevated privileges or the ability to load custom kernel modules. If successfully triggered, the resulting resource leak could lead to system instability or memory exhaustion, but the attack surface stays restricted to environments where the attacker can influence kernel module loading.

Generated by OpenCVE AI on September 20, 2026 at 01:52 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that contains the fix for the module initialization cleanup bug
  • Apply the kernel patch from the upstream source control if an updated kernel release is not available
  • Restrict kernel module loading to trusted administrative users and disable unneeded network services that may trigger the vulnerable code path

Generated by OpenCVE AI on September 20, 2026 at 01:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 02:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-401

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: smb/server: call ksmbd_proc_cleanup() on module init failure When a later initializer fails, the unwind chain releases resources created after procfs and then jumps directly to class_unregister(). Returning an error from module_init() leaves the proc tree and its per-CPU counters allocated.
Title smb/server: call ksmbd_proc_cleanup() on module init failure
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:06:53.809Z

Reserved: 2026-09-11T19:38:34.790Z

Link: CVE-2026-90163

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:09.637

Modified: 2026-09-17T17:17:09.637

Link: CVE-2026-90163

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T02:00:13Z

Weaknesses
  • CWE-401

    Missing Release of Memory after Effective Lifetime