CVE-2026-23282
published 2026-03-25CVE-2026-23282: In the Linux kernel, the following vulnerability has been resolved: smb: client: fix oops due to uninitialised var in smb2_unlink() If SMB2_open_init() or…
PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.12%
2.2th percentile
In the Linux kernel, the following vulnerability has been resolved:
smb: client: fix oops due to uninitialised var in smb2_unlink()
If SMB2_open_init() or SMB2_close_init() fails (e.g. reconnect), the
iovs set @rqst will be left uninitialised, hence calling
SMB2_open_free(), SMB2_close_free() or smb2_set_related() on them will
oops.
Fix this by initialising @close_iov and @open_iov before setting them
in @rqst.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.19.8-1 (forky) | linux 6.19.8-1 (forky) |
| linux | linux | — | — |
| linux | linux | >= 1cf9f2a6a544288516a7b9e883a48eba6246bcf2 < 86163b98891aa9800f6103252e5acc7bb98afb91 | 86163b98891aa9800f6103252e5acc7bb98afb91 |
| linux | linux | >= 1cf9f2a6a544288516a7b9e883a48eba6246bcf2 < dc710c87af3341554d02d634ada1d2036c49a94a | dc710c87af3341554d02d634ada1d2036c49a94a |
| linux | linux | >= 1cf9f2a6a544288516a7b9e883a48eba6246bcf2 < 048efe129a297256d3c2088cf8d79515ff5ec864 | 048efe129a297256d3c2088cf8d79515ff5ec864 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 6.19.8-1 | 6.19.8-1 |
| linux | linux_kernel | >= 6.17.0 < 6.18.17 | 6.18.17 |
| linux | linux_kernel | >= 6.17.1 < 6.18.17 | 6.18.17 |
| linux | linux_kernel | >= 6.19 < 6.19.7 | 6.19.7 |
| linux | linux_kernel | >= 6.19.0 < 6.19.7 | 6.19.7 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Linux Kernel up to 6.18.16/6.19.6/7.0-rc2 SMB Client smb2_unlink uninitialized resource (Nessus ID 311340 / WID-SEC-2026-0861)
vuldb·2026-05-22·CVSS 5.5
CVE-2026-23282 [MEDIUM] Linux Kernel up to 6.18.16/6.19.6/7.0-rc2 SMB Client smb2_unlink uninitialized resource (Nessus ID 311340 / WID-SEC-2026-0861)
A vulnerability, which was classified as critical, was found in Linux Kernel up to 6.18.16/6.19.6/7.0-rc2. This affects the function smb2_unlink of the component SMB Client. The manipulation results in uninitialized resource.
This vulnerability was named CVE-2026-23282. The attack needs to be approached within the local network. There is no available exploit.
You should upgrade the affected component.
OSV
CVE-2026-23282: In the Linux kernel, the following vulnerability has been resolved: smb: client: fix oops due to uninitialised var in smb2_unlink() If SMB2_open_init(
osv·2026-03-25
CVE-2026-23282 CVE-2026-23282: In the Linux kernel, the following vulnerability has been resolved: smb: client: fix oops due to uninitialised var in smb2_unlink() If SMB2_open_init(
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix oops due to uninitialised var in smb2_unlink() If SMB2_open_init() or SMB2_close_init() fails (e.g. reconnect), the iovs set @rqst will be left uninitialised, hence calling SMB2_open_free(), SMB2_close_free() or smb2_set_related() on them will oops. Fix this by initialising @close_iov and @open_iov before setting them in @rqst.
OSV
smb: client: fix oops due to uninitialised var in smb2_unlink()
osv·2026-03-25
CVE-2026-23282 smb: client: fix oops due to uninitialised var in smb2_unlink()
smb: client: fix oops due to uninitialised var in smb2_unlink()
In the Linux kernel, the following vulnerability has been resolved:
smb: client: fix oops due to uninitialised var in smb2_unlink()
If SMB2_open_init() or SMB2_close_init() fails (e.g. reconnect), the
iovs set @rqst will be left uninitialised, hence calling
SMB2_open_free(), SMB2_close_free() or smb2_set_related() on them will
oops.
Fix this by initialising @close_iov and @open_iov before setting them
in @rqst.
GHSA
GHSA-xc6w-xcgh-jjhw: In the Linux kernel, the following vulnerability has been resolved:
smb: client: fix oops due to uninitialised var in smb2_unlink()
If SMB2_open_ini
ghsa_unreviewed·2026-03-25
CVE-2026-23282 GHSA-xc6w-xcgh-jjhw: In the Linux kernel, the following vulnerability has been resolved:
smb: client: fix oops due to uninitialised var in smb2_unlink()
If SMB2_open_ini
In the Linux kernel, the following vulnerability has been resolved:
smb: client: fix oops due to uninitialised var in smb2_unlink()
If SMB2_open_init() or SMB2_close_init() fails (e.g. reconnect), the
iovs set @rqst will be left uninitialised, hence calling
SMB2_open_free(), SMB2_close_free() or smb2_set_related() on them will
oops.
Fix this by initialising @close_iov and @open_iov before setting them
in @rqst.
Red Hat
kernel: smb: client: fix oops due to uninitialised var in smb2_unlink()
vendor_redhat·2026-03-25·CVSS 5.5
CVE-2026-23282 [MEDIUM] CWE-824 kernel: smb: client: fix oops due to uninitialised var in smb2_unlink()
kernel: smb: client: fix oops due to uninitialised var in smb2_unlink()
In the Linux kernel, the following vulnerability has been resolved:
smb: client: fix oops due to uninitialised var in smb2_unlink()
If SMB2_open_init() or SMB2_close_init() fails (e.g. reconnect), the
iovs set @rqst will be left uninitialised, hence calling
SMB2_open_free(), SMB2_close_free() or smb2_set_related() on them will
oops.
Fix this by initialising @close_iov and @open_iov before setting them
in @rqst.
A flaw was found in the Linux kernel's Server Message Block (SMB) client. This vulnerability occurs when the SMB client fails to properly initialize variables during certain connection operations, such as reconnecting. An uninitialized variable can then be used, leading to a kernel panic and causing a Denial o
Debian
CVE-2026-23282: linux - In the Linux kernel, the following vulnerability has been resolved: smb: client...
vendor_debian·2026
CVE-2026-23282 [LOW] CVE-2026-23282: linux - In the Linux kernel, the following vulnerability has been resolved: smb: client...
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix oops due to uninitialised var in smb2_unlink() If SMB2_open_init() or SMB2_close_init() fails (e.g. reconnect), the iovs set @rqst will be left uninitialised, hence calling SMB2_open_free(), SMB2_close_free() or smb2_set_related() on them will oops. Fix this by initialising @close_iov and @open_iov before setting them in @rqst.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 6.19.8-1)
sid: resolved (fixed in 6.19.8-1)
trixie: resolved
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-23282 kernel: smb: client: fix oops due to uninitialised var in smb2_unlink()
bugzilla·2026-03-25·CVSS 5.5
CVE-2026-23282 [MEDIUM] CVE-2026-23282 kernel: smb: client: fix oops due to uninitialised var in smb2_unlink()
CVE-2026-23282 kernel: smb: client: fix oops due to uninitialised var in smb2_unlink()
In the Linux kernel, the following vulnerability has been resolved:
smb: client: fix oops due to uninitialised var in smb2_unlink()
If SMB2_open_init() or SMB2_close_init() fails (e.g. reconnect), the
iovs set @rqst will be left uninitialised, hence calling
SMB2_open_free(), SMB2_close_free() or smb2_set_related() on them will
oops.
Fix this by initialising @close_iov and @open_iov before setting them
in @rqst.
Discussion:
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2026032523-CVE-2026-23282-bad0@gregkh/T
Wiz
CVE-2026-23282 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz
CVE-2026-23282 CVE-2026-23282 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-23282 :
Linux Kernel vulnerability analysis and mitigation
In the Linux kernel, the following vulnerability has been resolved:
smb: client: fix oops due to uninitialised var in smb2_unlink()
If SMB2_open_init() or SMB2_close_init() fails (e.g. reconnect), the
iovs set @rqst will be left uninitialised, hence calling
SMB2_open_free(), SMB2_close_free() or smb2_set_related() on them will
oops.
Fix this by initialising @close_iov and @open_iov before setting them
in @rqst.
Source : NVD
Published March 25, 2026
CNA Score N/A
Affected Technologies
Linux Kernel
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 5.9
Exploitation Probability (EPSS) N/A
Affected packages a
2026-03-25
Published