Description
In the Linux kernel, the following vulnerability has been resolved:

ksmbd: free preauth sessions on connection teardown

SMB3.1.1 multichannel binding preserves the preauthentication hash in a
preauth_session between the NTLM negotiate and authenticate requests.
The binding NTLM negotiate allocates this object and returns
STATUS_MORE_PROCESSING_REQUIRED. If the client disconnects before it sends
the authenticate request, neither the authenticate nor error cleanup paths
free the object.

Release any remaining preauthentication sessions when tearing down the
connection. Initialize the list when allocating the connection so that this
cleanup is safe regardless of the negotiated dialect.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch
AI Analysis

Impact

The Linux kernel’s ksmbd module does not free preauthentication sessions that are allocated during SMB3.1.1 multichannel binding when a client disconnects before completing authentication. Each such connection tear‑down leaves a preauth_session object in memory. The accumulated leaked objects can increase kernel memory usage over time, which may degrade system performance or lead to resource exhaustion.

Affected Systems

All Linux kernel builds that include the ksmbd SMBv3 implementation and accept SMB3.1.1 multichannel traffic are affected until the kernel update that introduces the preauth_session cleanup on connection teardown is applied. The issue applies to any system running a Linux kernel that offers SMB services over port 445 and has not yet upgraded to a version containing the commit that releases preauthentication sessions.

Risk and Exploitability

The EPSS score is less than 1%, indicating a very low probability of exploitation at this time, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is a network client connecting to the SMB service on port 445 that sends an NTLM negotiate request for SMB3.1.1 multichannel binding and then terminates the connection before sending an authenticate request. No authentication or administrative privileges are required to trigger the leak. When repeatedly exploited, the accumulated leaked objects have the potential to exhaust kernel memory, which could cause the system to become unresponsive or crash.

Generated by OpenCVE AI on September 20, 2026 at 02:45 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Linux kernel update that includes the ksmbd preauthentication session cleanup fix
  • If a kernel upgrade cannot be applied immediately, restrict SMB traffic by blocking or rate‑limiting port 445 or disabling SMB3.1.1 multichannel binding if not required
  • Continuously monitor system memory usage and SMB connection statistics for anomalous growth in preauthentication session counts

Generated by OpenCVE AI on September 20, 2026 at 02:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sun, 20 Sep 2026 03:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-401

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: ksmbd: free preauth sessions on connection teardown SMB3.1.1 multichannel binding preserves the preauthentication hash in a preauth_session between the NTLM negotiate and authenticate requests. The binding NTLM negotiate allocates this object and returns STATUS_MORE_PROCESSING_REQUIRED. If the client disconnects before it sends the authenticate request, neither the authenticate nor error cleanup paths free the object. Release any remaining preauthentication sessions when tearing down the connection. Initialize the list when allocating the connection so that this cleanup is safe regardless of the negotiated dialect.
Title ksmbd: free preauth sessions on connection teardown
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:06:57.814Z

Reserved: 2026-09-11T19:38:34.790Z

Link: CVE-2026-90169

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:10.333

Modified: 2026-09-17T17:17:10.333

Link: CVE-2026-90169

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T03:00:11Z

Weaknesses
  • CWE-401

    Missing Release of Memory after Effective Lifetime