cbcvebase.
CVE-2026-23228
published 2026-02-18

CVE-2026-23228: In the Linux kernel, the following vulnerability has been resolved: smb: server: fix leak of active_num_conn in ksmbd_tcp_new_connection() On kthread_run()…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.12%
2.0th percentile
In the Linux kernel, the following vulnerability has been resolved: smb: server: fix leak of active_num_conn in ksmbd_tcp_new_connection() On kthread_run() failure in ksmbd_tcp_new_connection(), the transport is freed via free_transport(), which does not decrement active_num_conn, leaking this counter. Replace free_transport() with ksmbd_tcp_disconnect().

Affected

66 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.164-1 (bookworm)linux 6.1.164-1 (bookworm)
debianlinux-6.1< linux 6.1.164-1 (bookworm)linux 6.1.164-1 (bookworm)
linuxlinux
linuxlinux>= 0d0d4680db22eda1eea785c47bbf66a9b33a8b16 < 787769c8cc50416af7b8b1a36e6bcd6aaa7680aa787769c8cc50416af7b8b1a36e6bcd6aaa7680aa
linuxlinux>= 0d0d4680db22eda1eea785c47bbf66a9b33a8b16 < baf664fc90a6139a39a58333e4aaa390c10d45dcbaf664fc90a6139a39a58333e4aaa390c10d45dc
linuxlinux>= 0d0d4680db22eda1eea785c47bbf66a9b33a8b16 < cd25e0d809531a67e9dd53b19012d27d2b13425fcd25e0d809531a67e9dd53b19012d27d2b13425f
linuxlinux>= 0d0d4680db22eda1eea785c47bbf66a9b33a8b16 < 599271110c35f6b16e2e4e45b9fbd47ed378c982599271110c35f6b16e2e4e45b9fbd47ed378c982
linuxlinux>= 0d0d4680db22eda1eea785c47bbf66a9b33a8b16 < 77ffbcac4e569566d0092d5f22627dfc0896b55377ffbcac4e569566d0092d5f22627dfc0896b553
linuxlinux>= 4210c3555db4b38bade92331b153e583261f05f9 < 6dd2645cf080a75be31fa66063c7332b291f46f06dd2645cf080a75be31fa66063c7332b291f46f0
linuxlinux>= 5.15.91 < 5.15.2015.15.201
linuxlinux>= 6.1.9 < 6.1.1646.1.164
linuxlinux>= d5d7847e57ac69fa99c18b363a34419bcdb5a281 < 7ddd69cd1338c6197e1b6b19cec60d99c8633e4f7ddd69cd1338c6197e1b6b19cec60d99c8633e4f
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.164-16.1.164-1
linuxlinux_kernel>= 0 < 6.12.73-16.12.73-1
linuxlinux_kernel>= 0 < 6.18.12-16.18.12-1
linuxlinux_kernel>= 5.15.91 < 5.15.2015.15.201
linuxlinux_kernel>= 6.1.9 < 6.1.1646.1.164
linuxlinux_kernel>= 6.13 < 6.18.116.18.11
linuxlinux_kernel>= 6.19 < 6.19.16.19.1
linuxlinux_kernel>= 6.2.1 < 6.6.1256.6.125
linuxlinux_kernel>= 6.7 < 6.12.726.12.72
msrcazl3_kernel_6.6.121.1-1_on_azure_linux_3.0
msrccbl2_kernel_5.15.200.1-1_on_cbl_mariner_2.0
ubuntulinux

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_ubuntu8.8HIGH
vendor_msrc6.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.