CVE-2026-64396

8.8

Linux · Kernel

A use-after-free vulnerability in the Linux kernel ksmbd subsystem allows low-privileged attackers to cause a denial of service or execute arbitrary code via SMB2 lock cancellation.

Executive summary

A use-after-free vulnerability in the Linux kernel ksmbd subsystem allows low-privileged network attackers to compromise system integrity and availability.

Vulnerability

This flaw involves a use-after-free condition within the ksmbd subsystem during SMB2 deferred-lock cancellation, triggered by low-privileged authenticated users over the network.

Business impact

A successful exploitation of this vulnerability can lead to severe system instability, kernel panics, or arbitrary code execution with high privileges. The CVSS score of 8.8 classifies this as a high-severity issue, threatening operational continuity and data integrity across affected servers.

Remediation

Immediate Action: Update the Linux kernel to version 6.1.178, 6.6.145, 6.12.96, 6.18.39, or later depending on the active release branch.

Proactive Monitoring: Monitor system logs for kernel panics, unexpected reboots, or anomalies related to ksmbd network activity.

Compensating Controls: Restrict network access to the ksmbd service to trusted administrative networks using host-based firewalls or network segmentation.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the high CVSS score and the potential for severe system compromise via the kernel, administrators should prioritize applying the official kernel patches immediately. Testing and deploying these updates in staging environments will prevent widespread operational disruptions.

More Linux CVEs

Sources