Description
In the Linux kernel, the following vulnerability has been resolved:

smb/server: abort initialization when proc setup fails

ksmbd_server_init() calls ksmbd_proc_init() before creating the
remaining proc entries and server subsystems. ksmbd_proc_init() tears
down partial state on a procfs or percpu_counter allocation failure,
but returns void, so ksmbd_server_init() continues as if the counters
were usable.

Once userspace starts the server, server_ctrl_handle_init() calls
ksmbd_proc_reset(), which reaches percpu_counter_set() with a NULL
per-CPU counters pointer on SMP systems. The later ksmbd_proc_create()
calls also receive a NULL parent and may create entries in the /proc
root; ksmbd_proc_cleanup() cannot remove those entries because
ksmbd_proc_fs is NULL.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service (Kernel Crash)
Action: Immediate Patch
AI Analysis

Impact

The Linux kernel’s SMB server initialization routine incorrectly continues when the process‑setup step fails. A null pointer dereference during counter reset causes a kernel panic, which results in a denial‑of‑service condition. The vulnerability is an instance of a null‑pointer dereference weakness (CWE‑476). The crash occurs after a userspace client initiates the server, so the likely attack vector is a remote SMB connection that triggers the server startup path. The impact is that a single malformed or unclean SMB session can bring the entire host down, potentially affecting availability for all users and services hosted on the affected machine. The fault is exposed on all Linux systems that build the ksmbd kernel module, regardless of distribution, as the kernel source is common to all releases. No specific version numbers are provided, so any kernel that has not yet been patched for this issue is vulnerable. Risk assessment indicates that the EPSS score is below 1%, showing a low predicted exploitation probability in the wild. The vulnerability is not listed in the CISA KEV catalog and the CVSS severity is not disclosed in the supplied data. However, because the flaw leads directly to a kernel panic, the potential loss of availability is high, but practical exploitation is considered unlikely without a committed attacker. }

Affected Systems

All Linux kernels that include the ksmbd SMB server module are affected. The vulnerability is present in the kernel source regardless of distribution (Linux:Linux). No specific product versions are identified in the report, so all installations lacking a recent patch are potentially vulnerable.

Risk and Exploitability

The flaw is a low‑probability but high‑impact kernel‑panic condition caused by a null‑pointer dereference during SMB server start‑up. The EPSS score of less than 1% suggests that attacks are not widely observed, and the vulnerability is not yet featured in the CISA KEV catalog. Nonetheless, the CVE demonstrates a direct path from a remote SMB client to a kernel crash; systems that expose an SMB server should treat this as a critical availability risk.

Generated by OpenCVE AI on September 20, 2026 at 01:52 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a kernel update that includes the ksmbd initialization fix (consult the kernel changelog for commits db97f376… or fb4ba2bd… where the patch was applied).
  • If an update is not yet available, consider disabling the ksmbd SMB module or restricting its use to trusted networks, restricting unauthorized SMB access via firewall or ACLs.
  • Configure monitoring or alerting for kernel panic events to detect any attempts to exploit the flaw.

Generated by OpenCVE AI on September 20, 2026 at 01:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 02:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: smb/server: abort initialization when proc setup fails ksmbd_server_init() calls ksmbd_proc_init() before creating the remaining proc entries and server subsystems. ksmbd_proc_init() tears down partial state on a procfs or percpu_counter allocation failure, but returns void, so ksmbd_server_init() continues as if the counters were usable. Once userspace starts the server, server_ctrl_handle_init() calls ksmbd_proc_reset(), which reaches percpu_counter_set() with a NULL per-CPU counters pointer on SMP systems. The later ksmbd_proc_create() calls also receive a NULL parent and may create entries in the /proc root; ksmbd_proc_cleanup() cannot remove those entries because ksmbd_proc_fs is NULL.
Title smb/server: abort initialization when proc setup fails
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:06:54.504Z

Reserved: 2026-09-11T19:38:34.790Z

Link: CVE-2026-90164

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:09.747

Modified: 2026-09-17T17:17:09.747

Link: CVE-2026-90164

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T02:00:13Z

Weaknesses