Description
In the Linux kernel, the following vulnerability has been resolved:

smb/server: fix null-ptr-deref in ksmbd_ipc_tree_connect_request()

See the procedure below:

ksmbd_tree_conn_connect
ksmbd_share_config_get
share->name = kstrdup() // fail
if (!test_share_config_flag(share, KSMBD_SHARE_FLAG_PIPE)) // false
// do not check `share->name`
ksmbd_ipc_tree_connect_request
strlen(share->name) // null-ptr-deref
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch
AI Analysis

Impact

A null pointer dereference occurs in the kernel's SMB (smbd) server when handling an IPC tree connect request. The failure to validate the return value of kstrdup() leaves a NULL share name unchecked, which the next call to strlen() crashes the kernel. This leads to a system‑wide crash and loss of service rather than execution of arbitrary code.

Affected Systems

The flaw is present in the Linux kernel’s smb server component (smbd) on any distribution that has not yet applied the fix. The specific kernel versions are not enumerated in the data, but all kernels containing the unpatched smbd module are affected.

Risk and Exploitability

An attacker could trigger the crash by initiating an IPC tree connect request over SMB, which is typically a remote attack vector. The EPSS score is less than 1%, suggesting a low exploitation likelihood, and the vulnerability is not listed in CISA’s KEV catalog. The impact is limited to denial of service because the flaw causes a kernel panic rather than granting code execution or elevated privileges.

Generated by OpenCVE AI on September 20, 2026 at 01:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a kernel update that includes the patch for the ksmbd_ipc_tree_connect_request null pointer dereference
  • Reboot the system to load the updated kernel and verify the smbd module is using the corrected code
  • If an immediate kernel update is not possible, consider disabling the ksmbd module or the SMB service to prevent remote exploitation

Generated by OpenCVE AI on September 20, 2026 at 01:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sun, 20 Sep 2026 02:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: smb/server: fix null-ptr-deref in ksmbd_ipc_tree_connect_request() See the procedure below: ksmbd_tree_conn_connect ksmbd_share_config_get share->name = kstrdup() // fail if (!test_share_config_flag(share, KSMBD_SHARE_FLAG_PIPE)) // false // do not check `share->name` ksmbd_ipc_tree_connect_request strlen(share->name) // null-ptr-deref
Title smb/server: fix null-ptr-deref in ksmbd_ipc_tree_connect_request()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:06:55.863Z

Reserved: 2026-09-11T19:38:34.790Z

Link: CVE-2026-90166

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:09.980

Modified: 2026-09-17T17:17:09.980

Link: CVE-2026-90166

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T02:00:13Z

Weaknesses