CVE-2026-23226
published 2026-02-18CVE-2026-23226: In the Linux kernel, the following vulnerability has been resolved: ksmbd: add chann_lock to protect ksmbd_chann_list xarray ksmbd_chann_list xarray lacks…
PriorityP340high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.42%
34.3th percentile
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: add chann_lock to protect ksmbd_chann_list xarray
ksmbd_chann_list xarray lacks synchronization, allowing use-after-free in
multi-channel sessions (between lookup_chann_list() and ksmbd_chann_del).
Adds rw_semaphore chann_lock to struct ksmbd_session and protects
all xa_load/xa_store/xa_erase accesses.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.18.12-1 (forky) | linux 6.18.12-1 (forky) |
| linux | linux | — | — |
| linux | linux | — | — |
| linux | linux | — | — |
| linux | linux | — | — |
| linux | linux | >= 1d9c4172110e645b383ff13eee759728d74f1a5d < 4c2ca31608521895dd742a43beca4b4d29762345 | 4c2ca31608521895dd742a43beca4b4d29762345 |
| linux | linux | >= 1d9c4172110e645b383ff13eee759728d74f1a5d < e4a8a96a93d08570e0405cfd989a8a07e5b6ff33 | e4a8a96a93d08570e0405cfd989a8a07e5b6ff33 |
| linux | linux | >= 1d9c4172110e645b383ff13eee759728d74f1a5d < 36ef605c0395b94b826a8c8d6f2697071173de6e | 36ef605c0395b94b826a8c8d6f2697071173de6e |
| linux | linux | >= 1d9c4172110e645b383ff13eee759728d74f1a5d < 4f3a06cc57976cafa8c6f716646be6c79a99e485 | 4f3a06cc57976cafa8c6f716646be6c79a99e485 |
| linux | linux | >= 5.15.145 < 5.16 | 5.16 |
| linux | linux | >= 6.1.29 < 6.2 | 6.2 |
| linux | linux | >= 6.2.16 < 6.3 | 6.3 |
| linux | linux_kernel | >= 0 < 6.18.12-1 | 6.18.12-1 |
| linux | linux_kernel | >= 6.19 < 6.19.1 | 6.19.1 |
| linux | linux_kernel | >= 6.3 < 6.18.11 | 6.18.11 |
| msrc | azl3_kernel_6.6.121.1-1_on_azure_linux_3.0 | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
vendor_msrc7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Linux Kernel up to 6.18.10/6.19.0 ksmbd lookup_chann_list use after free (EUVD-2026-7675 / Nessus ID 299441)
vuldb·2026-05-24·CVSS 7.8
CVE-2026-23226 [HIGH] Linux Kernel up to 6.18.10/6.19.0 ksmbd lookup_chann_list use after free (EUVD-2026-7675 / Nessus ID 299441)
A vulnerability marked as critical has been reported in Linux Kernel up to 6.18.10/6.19.0. The affected element is the function lookup_chann_list of the component ksmbd. Performing a manipulation results in use after free.
This vulnerability is cataloged as CVE-2026-23226. The attack must originate from the local network. There is no exploit available.
It is suggested to upgrade the affected component.
OSV
CVE-2026-23226: In the Linux kernel, the following vulnerability has been resolved: ksmbd: add chann_lock to protect ksmbd_chann_list xarray ksmbd_chann_list xarray l
osv·2026-02-18·CVSS 7.8
CVE-2026-23226 [HIGH] CVE-2026-23226: In the Linux kernel, the following vulnerability has been resolved: ksmbd: add chann_lock to protect ksmbd_chann_list xarray ksmbd_chann_list xarray l
In the Linux kernel, the following vulnerability has been resolved: ksmbd: add chann_lock to protect ksmbd_chann_list xarray ksmbd_chann_list xarray lacks synchronization, allowing use-after-free in multi-channel sessions (between lookup_chann_list() and ksmbd_chann_del). Adds rw_semaphore chann_lock to struct ksmbd_session and protects all xa_load/xa_store/xa_erase accesses.
GHSA
GHSA-5jgq-pv8m-5cx7: In the Linux kernel, the following vulnerability has been resolved:
ksmbd: add chann_lock to protect ksmbd_chann_list xarray
ksmbd_chann_list xarray
ghsa_unreviewed·2026-02-18
CVE-2026-23226 [HIGH] CWE-416 GHSA-5jgq-pv8m-5cx7: In the Linux kernel, the following vulnerability has been resolved:
ksmbd: add chann_lock to protect ksmbd_chann_list xarray
ksmbd_chann_list xarray
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: add chann_lock to protect ksmbd_chann_list xarray
ksmbd_chann_list xarray lacks synchronization, allowing use-after-free in
multi-channel sessions (between lookup_chann_list() and ksmbd_chann_del).
Adds rw_semaphore chann_lock to struct ksmbd_session and protects
all xa_load/xa_store/xa_erase accesses.
Red Hat
kernel: ksmbd: add chann_lock to protect ksmbd_chann_list xarray
vendor_redhat·2026-02-18·CVSS 8.8
CVE-2026-23226 [HIGH] kernel: ksmbd: add chann_lock to protect ksmbd_chann_list xarray
kernel: ksmbd: add chann_lock to protect ksmbd_chann_list xarray
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: add chann_lock to protect ksmbd_chann_list xarray
ksmbd_chann_list xarray lacks synchronization, allowing use-after-free in
multi-channel sessions (between lookup_chann_list() and ksmbd_chann_del).
Adds rw_semaphore chann_lock to struct ksmbd_session and protects
all xa_load/xa_store/xa_erase accesses.
Package: kernel (Red Hat Enterprise Linux 10) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Not affected
Package: kernel (Red Hat Enterprise Linux 8) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux
Microsoft
ksmbd: add chann_lock to protect ksmbd_chann_list xarray
vendor_msrc·2026-02-10·CVSS 7.5
CVE-2026-23226 [HIGH] ksmbd: add chann_lock to protect ksmbd_chann_list xarray
ksmbd: add chann_lock to protect ksmbd_chann_list xarray
Mariner: Mariner
Linux: Linux
Customer Action Required: Yes
Debian
CVE-2026-23226: linux - In the Linux kernel, the following vulnerability has been resolved: ksmbd: add ...
vendor_debian·2026·CVSS 8.8
CVE-2026-23226 [HIGH] CVE-2026-23226: linux - In the Linux kernel, the following vulnerability has been resolved: ksmbd: add ...
In the Linux kernel, the following vulnerability has been resolved: ksmbd: add chann_lock to protect ksmbd_chann_list xarray ksmbd_chann_list xarray lacks synchronization, allowing use-after-free in multi-channel sessions (between lookup_chann_list() and ksmbd_chann_del). Adds rw_semaphore chann_lock to struct ksmbd_session and protects all xa_load/xa_store/xa_erase accesses.
Scope: local
bookworm: open
bullseye: resolved
forky: resolved (fixed in 6.18.12-1)
sid: resolved (fixed in 6.18.12-1)
trixie: open
No detection rules found.
No public exploits indexed.
Hackernews
ThreatsDay Bulletin: Hybrid P2P Botnet, 13-Year-Old Apache RCE and 18 More Stories
blogs_hackernews·2026-04-09
ThreatsDay Bulletin: Hybrid P2P Botnet, 13-Year-Old Apache RCE and 18 More Stories
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ThreatsDay Bulletin: Hybrid P2P Botnet, 13-Year-Old Apache RCE and 18 More Stories
Thursday. Another week, another batch of things that probably should've been caught sooner but weren't.
This one's got some range — old vulnerabilities getting new life, a few "why was that even possible" moments, attackers leaning on platforms and tools you'd normally trust without thinking twice. Quiet escalations more than loud zero-days, but the kind that matter more in practice anyway.
Mix of malware, infrastructure exposure, AI-adjacent weirdness, and some supply chain stuff that's... not great. Let's get into it.
A new variant of the
Wiz
CVE-2026-23226 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-23226 [HIGH] CVE-2026-23226 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-23226 :
Linux Debian vulnerability analysis and mitigation
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: add chann_lock to protect ksmbd_chann_list xarray
ksmbd_chann_list xarray lacks synchronization, allowing use-after-free in
multi-channel sessions (between lookup_chann_list() and ksmbd_chann_del).
Adds rw_semaphore chann_lock to struct ksmbd_session and protects
all xa_load/xa_store/xa_erase accesses.
Source : NVD
## 7.8
Score
Published February 18, 2026
Severity HIGH
CNA Score 8.8
Affected Technologies
Linux Debian
Linux Ubuntu
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 5.7
Exploitation Probability (EPSS) N/A
Affected packages an
2026-02-18
Published