Impact
The Linux kernel’s ksmbd module does not free preauthentication sessions that are allocated during SMB3.1.1 multichannel binding when a client disconnects before completing authentication. Each such connection tear‑down leaves a preauth_session object in memory. The accumulated leaked objects can increase kernel memory usage over time, which may degrade system performance or lead to resource exhaustion.
Affected Systems
All Linux kernel builds that include the ksmbd SMBv3 implementation and accept SMB3.1.1 multichannel traffic are affected until the kernel update that introduces the preauth_session cleanup on connection teardown is applied. The issue applies to any system running a Linux kernel that offers SMB services over port 445 and has not yet upgraded to a version containing the commit that releases preauthentication sessions.
Risk and Exploitability
The EPSS score is less than 1%, indicating a very low probability of exploitation at this time, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is a network client connecting to the SMB service on port 445 that sends an NTLM negotiate request for SMB3.1.1 multichannel binding and then terminates the connection before sending an authenticate request. No authentication or administrative privileges are required to trigger the leak. When repeatedly exploited, the accumulated leaked objects have the potential to exhaust kernel memory, which could cause the system to become unresponsive or crash.
OpenCVE Enrichment
Debian DLA
Debian DSA