cbcvebase.
CVE-2026-23427
published 2026-04-03

CVE-2026-23427: In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in durable v2 replay of active file handles…

PriorityP340high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.29%
21.3th percentile
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in durable v2 replay of active file handles parse_durable_handle_context() unconditionally assigns dh_info->fp->conn to the current connection when handling a DURABLE_REQ_V2 context with SMB2_FLAGS_REPLAY_OPERATION. ksmbd_lookup_fd_cguid() does not filter by fp->conn, so it returns file handles that are already actively connected. The unconditional overwrite replaces fp->conn, and when the overwriting connection is subsequently freed, __ksmbd_close_fd() dereferences the stale fp->conn via spin_lock(&fp->conn->llist_lock), causing a use-after-free. KASAN report: [ 7.349357] ================================================================== [ 7.349607] BUG: KASAN: slab-use-after-free in _raw_spin_lock+0x75/0xe0 [ 7.349811] Write of size 4 at addr ffff8881056ac18c by task kworker/1:2/108 [ 7.350010] [ 7.350064] CPU: 1 UID: 0 PID: 108 Comm: kworker/1:2 Not tainted 7.0.0-rc3+ #58 PREEMPTLAZY [ 7.350068] Hardware name: QEMU Ubuntu 24.04 PC v2 (i440FX + PIIX, arch_caps fix, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014 [ 7.350070] Workqueue: ksmbd-io handle_ksmbd_work [ 7.350083] Call Trace: [ 7.350087] [ 7.350087] dump_stack_lvl+0x64/0x80 [ 7.350094] print_report+0xce/0x660 [ 7.350100] ? __pfx__raw_spin_lock_irqsave+0x10/0x10 [ 7.350101] ? __pfx___mod_timer+0x10/0x10 [ 7.350106] ? _raw_spin_lock+0x75/0xe0 [ 7.350108] kasan_report+0xce/0x100 [ 7.350109] ? _raw_spin_lock+0x75/0xe0 [ 7.350114] kasan_check_range+0x105/0x1b0 [ 7.350116] _raw_spin_lock+0x75/0xe0 [ 7.350118] ? __pfx__raw_spin_lock+0x10/0x10 [ 7.350119] ? __call_rcu_common.constprop.0+0x25e/0x780 [ 7.350125] ? close_id_del_oplock+0x2cc/0x4e0 [ 7.350128] __ksmbd_close_fd+0x27f/0xaf0 [ 7.350131] ksmbd_close_fd+0x135/0x1b0 [ 7.350133] smb2_close+0xb19/0x15b0 [ 7.350142] ? __pfx_smb2_close+0x10/0x10 [ 7.350143] ? xas_load+0x18/0x270 [ 7.350146] ? _raw_spin_lock+0x84/0xe0 [ 7.350148] ? __pfx__raw_spin_lock+0x10/0x10 [ 7.3

Affected

22 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.19.10-1 (forky)linux 6.19.10-1 (forky)
linuxlinux
linuxlinux>= 6.6.32 < 6.6.1306.6.130
linuxlinux>= 8df4bcdb0a4232192b2445256c39b787d58ef14d < b0158d9d6f4ec5941e49a0b812735db2844f9975b0158d9d6f4ec5941e49a0b812735db2844f9975
linuxlinux>= c8efcc786146a951091588e5fa7e3c754850cb3c < 568a25fd7bcdfb2790f7d42aa2a440dca4435c96568a25fd7bcdfb2790f7d42aa2a440dca4435c96
linuxlinux>= c8efcc786146a951091588e5fa7e3c754850cb3c < a5828c14a9e3d5eeed0bcc0a58f0f3fbca0cdcb2a5828c14a9e3d5eeed0bcc0a58f0f3fbca0cdcb2
linuxlinux>= c8efcc786146a951091588e5fa7e3c754850cb3c < 9b0792c3eacf01e67f356d6ef9707b0ae50224199b0792c3eacf01e67f356d6ef9707b0ae5022419
linuxlinux>= c8efcc786146a951091588e5fa7e3c754850cb3c < b425e4d0eb321a1116ddbf39636333181675d8f4b425e4d0eb321a1116ddbf39636333181675d8f4
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.19.10-16.19.10-1
linuxlinux_kernel>= 6.13 < 6.18.206.18.20
linuxlinux_kernel>= 6.19 < 6.19.106.19.10
linuxlinux_kernel>= 6.6.32 < 6.6.1306.6.130
linuxlinux_kernel>= 6.9.1 < 6.12.786.12.78
ubuntulinux
ubuntulinux-azure-6.17
ubuntulinux-azure-fde-6.17
ubuntulinux-hwe-6.17
ubuntulinux-nvidia-6.17
ubuntulinux-oem-6.17
ubuntulinux-raspi

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_ubuntu7.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.