cbcvebase.
CVE-2026-23205
published 2026-02-14

CVE-2026-23205: In the Linux kernel, the following vulnerability has been resolved: smb/client: fix memory leak in smb2_open_file() Reproducer: 1. server: directories are…

PriorityP417medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.11%
1.7th percentile
In the Linux kernel, the following vulnerability has been resolved: smb/client: fix memory leak in smb2_open_file() Reproducer: 1. server: directories are exported read-only 2. client: mount -t cifs //${server_ip}/export /mnt 3. client: dd if=/dev/zero of=/mnt/file bs=512 count=1000 oflag=direct 4. client: umount /mnt 5. client: sleep 1 6. client: modprobe -r cifs The error message is as follows: BUG cifs_small_rq (Not tainted): Objects remaining on __kmem_cache_shutdown() Object 0x00000000d47521be @offset=14336 ... WARNING: mm/slub.c:1251 at __kmem_cache_shutdown+0x34e/0x440, CPU#0: modprobe/1577 ... Call Trace: kmem_cache_destroy+0x94/0x190 cifs_destroy_request_bufs+0x3e/0x50 [cifs] cleanup_module+0x4e/0x540 [cifs] __se_sys_delete_module+0x278/0x400 __x64_sys_delete_module+0x5f/0x70 x64_sys_call+0x2299/0x2ff0 do_syscall_64+0x89/0x350 entry_SYSCALL_64_after_hwframe+0x76/0x7e ... kmem_cache_destroy cifs_small_rq: Slab cache still has objects when called from cifs_destroy_request_bufs+0x3e/0x50 [cifs] WARNING: mm/slab_common.c:532 at kmem_cache_destroy+0x16b/0x190, CPU#0: modprobe/1577

Affected

45 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.164-1 (bookworm)linux 6.1.164-1 (bookworm)
debianlinux-6.1< linux 6.1.164-1 (bookworm)linux 6.1.164-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux>= 17e53a15e64b65623b8f2b1185d27d7b1cbf69ab < 743f70406264348c0830f38409eb6c40a42fb2db743f70406264348c0830f38409eb6c40a42fb2db
linuxlinux>= 18066188eb90cc0c798f3370a8078a79ddb73f70 < 3a6d6b332f92990958602c1e35ce0173e2dd62e93a6d6b332f92990958602c1e35ce0173e2dd62e9
linuxlinux>= 6.1.141 < 6.1.1636.1.163
linuxlinux>= 6.12.31 < 6.12.706.12.70
linuxlinux>= 6.14.9 < 6.156.15
linuxlinux>= 6.6.93 < 6.6.1246.6.124
linuxlinux>= 6ebb9d54eccc8026b386e76eff69364d33373da5 < b64e3b5d8d759dd4333992e4ba4dadf9359952c8b64e3b5d8d759dd4333992e4ba4dadf9359952c8
linuxlinux>= e255612b5ed9f179abe8196df7c2ba09dd227900 < 9ee608a64e37cea5b4b13e436c559dd0fb2ad1b59ee608a64e37cea5b4b13e436c559dd0fb2ad1b5
linuxlinux>= e255612b5ed9f179abe8196df7c2ba09dd227900 < e3a43633023e3cacaca60d4b8972d084a2b06236e3a43633023e3cacaca60d4b8972d084a2b06236
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.164-16.1.164-1
linuxlinux_kernel>= 0 < 6.12.73-16.12.73-1
linuxlinux_kernel>= 0 < 6.18.10-16.18.10-1
linuxlinux_kernel>= 6.1.141 < 6.1.1636.1.163
linuxlinux_kernel>= 6.12.31 < 6.12.706.12.70
linuxlinux_kernel>= 6.14.9 < 6.18.106.18.10
linuxlinux_kernel>= 6.6.93 < 6.6.1246.6.124
ubuntulinux
ubuntulinux-aws
ubuntulinux-aws-fips
ubuntulinux-azure

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_ubuntu7.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.