Description
In the Linux kernel, the following vulnerability has been resolved:

smb/server: fix invalid pointer dereference in ksmbd_stop_durable_scavenger()

See the procedure below:

ksmbd_launch_ksmbd_durable_scavenger
durable_scavenger_running = true
server_conf.dh_task = kthread_run() // fail, dh_task is an ERR_PTR()

server_ctrl_handle_reset
ksmbd_stop_durable_scavenger
kthread_stop(server_conf.dh_task) // invalid pointer
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Kernel Crash
Action: Patch Immediately
AI Analysis

Impact

This vulnerability is an invalid pointer dereference in the Linux kernel SMB server routine ksmbd_stop_durable_scavenger. The flaw can trigger a kernel panic when the SMB server attempts to stop a scavenger thread that failed to start, resulting in a complete system outage. The weakness is a pointer dereference error (CWE-665).

Affected Systems

The flaw is in the generic Linux kernel, affecting any Linux distribution that ships an unpatched kernel version before the commit that fixes ksmbd_stop_durable_scavenger. Versions prior to that commit are vulnerable. The CNA lists the vendor as Linux:Linux.

Risk and Exploitability

The EPSS score is less than 1%, indicating a very low probability of exploitation in the wild, and the flaw is not listed in CISA’s KEV catalog. No CVSS score is present, but a kernel panic represents a severe impact. Attackers would need to trigger the conditions that cause the scavenger thread to fail then invoke a server reset, which is likely local or remote with sufficient privileges to execute SMB server operations; (Inferred from the description). Exploitation complexity remains high. Overall risk is moderate due to low exploit likelihood but high potential impact if exploited.

Generated by OpenCVE AI on September 20, 2026 at 02:47 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the official Linux kernel update that includes the ksmbd_stop_durable_scavenger fix (commit 3f8651f6bb).
  • Reboot the system to load the corrected kernel and verify that the SMB server starts without crashing.
  • If immediate updating is not possible, disable the SMB service until the kernel can be patched to prevent further crashes.

Generated by OpenCVE AI on September 20, 2026 at 02:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: smb/server: fix invalid pointer dereference in ksmbd_stop_durable_scavenger() See the procedure below: ksmbd_launch_ksmbd_durable_scavenger durable_scavenger_running = true server_conf.dh_task = kthread_run() // fail, dh_task is an ERR_PTR() server_ctrl_handle_reset ksmbd_stop_durable_scavenger kthread_stop(server_conf.dh_task) // invalid pointer
Title smb/server: fix invalid pointer dereference in ksmbd_stop_durable_scavenger()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:06:55.196Z

Reserved: 2026-09-11T19:38:34.790Z

Link: CVE-2026-90165

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:09.853

Modified: 2026-09-17T17:17:09.853

Link: CVE-2026-90165

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T03:00:11Z

Weaknesses

No weakness.