Description
In the Linux kernel, the following vulnerability has been resolved:

smb: server: fix leak of ksmbd_ipc_login_request_ext() returned buffer

Free it unconditionally after ksmbd_alloc_user() calls.

kmemleak splat:
unreferenced object 0xffff888103b83540 (size 192):
comm "pool-0", pid 16970, jiffies 4377290937
hex dump (first 32 bytes):
00 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 ................
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
backtrace (crc 408ccc66):
__kvmalloc_node_noprof+0x730/0x920
handle_generic_event+0xec/0x1a0 [ksmbd]
genl_family_rcv_msg_doit+0xe0/0x130
genl_rcv_msg+0x181/0x290
netlink_rcv_skb+0x4f/0x100
genl_rcv+0x28/0x40
netlink_unicast+0x1e6/0x2c0
netlink_sendmsg+0x20a/0x450
____sys_sendmsg+0x2e8/0x310
___sys_sendmsg+0x78/0xc0
__sys_sendmsg+0x63/0xc0
do_syscall_64+0xa1/0x670
entry_SYSCALL_64_after_hwframe+0x76/0x7e
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Information Leakage via kernel memory
Action: Assess Impact
AI Analysis

Impact

The vulnerability is a kernel‑level memory leak in the Linux SMB server; the ksmbd_ipc_login_request_ext() function returns a buffer that the code fails to free until after ksmbd_alloc_user() runs, leaving a dangling object detectable by kmemleak. The leaked object contains partially initialized data that could expose sensitive kernel memory contents. The flaw is a data exposure issue and does not provide a direct path to remote code execution. Based on the description, it is inferred that a process running with sufficient privileges could read the leaked object and access kernel memory that was not intended to be exposed.

Affected Systems

All Linux kernel releases that include the SMB server component prior to the commit that added the missing free operation are affected. This encompasses the standard kernel packages distributed by major Linux vendors, any kernel that matches the CPE for Linux kernel and contains the SMB server code. No specific version numbers are supplied in the advisory, so all kernels that incorporate the vulnerable SMB server are considered vulnerable.

Risk and Exploitability

The EPSS score is reported as < 1%, and the vulnerability is not listed in the CISA KEV catalog, indicating a low probability of exploitation. The likely attack vector is interaction with the SMB service, but no explicit attack pattern is provided in the advisory; based on the description, it is inferred that conditions that trigger the leak involve SMB traffic to the server. The impact is limited to information disclosure; there is no direct privilege escalation or remote code execution. For systems that do not expose SMB services or that restrict SMB traffic to trusted hosts, the overall risk is low.

Generated by OpenCVE AI on September 20, 2026 at 02:44 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that includes the commit fixing the ksmbd IPC login buffer leak.
  • Disable or restrict the SMB service (including SMBv1) to limit exposure to trusted networks.
  • Apply any vendor‑provided kernel security updates and backports as they become available.

Generated by OpenCVE AI on September 20, 2026 at 02:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sun, 20 Sep 2026 03:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: smb: server: fix leak of ksmbd_ipc_login_request_ext() returned buffer Free it unconditionally after ksmbd_alloc_user() calls. kmemleak splat: unreferenced object 0xffff888103b83540 (size 192): comm "pool-0", pid 16970, jiffies 4377290937 hex dump (first 32 bytes): 00 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 ................ 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ backtrace (crc 408ccc66): __kvmalloc_node_noprof+0x730/0x920 handle_generic_event+0xec/0x1a0 [ksmbd] genl_family_rcv_msg_doit+0xe0/0x130 genl_rcv_msg+0x181/0x290 netlink_rcv_skb+0x4f/0x100 genl_rcv+0x28/0x40 netlink_unicast+0x1e6/0x2c0 netlink_sendmsg+0x20a/0x450 ____sys_sendmsg+0x2e8/0x310 ___sys_sendmsg+0x78/0xc0 __sys_sendmsg+0x63/0xc0 do_syscall_64+0xa1/0x670 entry_SYSCALL_64_after_hwframe+0x76/0x7e
Title smb: server: fix leak of ksmbd_ipc_login_request_ext() returned buffer
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:07:01.769Z

Reserved: 2026-09-11T19:38:34.791Z

Link: CVE-2026-90175

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:11.227

Modified: 2026-09-17T17:17:11.227

Link: CVE-2026-90175

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T02:45:18Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor