cbcvebase.
CVE-2026-23428
published 2026-04-03

CVE-2026-23428: In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free of share_conf in compound request smb2_get_ksmbd_tcon() reuses…

PriorityP343high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.33%
25.7th percentile
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free of share_conf in compound request smb2_get_ksmbd_tcon() reuses work->tcon in compound requests without validating tcon->t_state. ksmbd_tree_conn_lookup() checks t_state == TREE_CONNECTED on the initial lookup path, but the compound reuse path bypasses this check entirely. If a prior command in the compound (SMB2_TREE_DISCONNECT) sets t_state to TREE_DISCONNECTED and frees share_conf via ksmbd_share_config_put(), subsequent commands dereference the freed share_conf through work->tcon->share_conf. KASAN report: [ 4.144653] ================================================================== [ 4.145059] BUG: KASAN: slab-use-after-free in smb2_write+0xc74/0xe70 [ 4.145415] Read of size 4 at addr ffff88810430c194 by task kworker/1:1/44 [ 4.145772] [ 4.145867] CPU: 1 UID: 0 PID: 44 Comm: kworker/1:1 Not tainted 7.0.0-rc3+ #60 PREEMPTLAZY [ 4.145871] Hardware name: QEMU Ubuntu 24.04 PC v2 (i440FX + PIIX, arch_caps fix, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014 [ 4.145875] Workqueue: ksmbd-io handle_ksmbd_work [ 4.145888] Call Trace: [ 4.145892] [ 4.145894] dump_stack_lvl+0x64/0x80 [ 4.145910] print_report+0xce/0x660 [ 4.145919] ? __pfx__raw_spin_lock_irqsave+0x10/0x10 [ 4.145928] ? smb2_write+0xc74/0xe70 [ 4.145931] kasan_report+0xce/0x100 [ 4.145934] ? smb2_write+0xc74/0xe70 [ 4.145937] smb2_write+0xc74/0xe70 [ 4.145939] ? __pfx_smb2_write+0x10/0x10 [ 4.145942] ? _raw_spin_unlock+0xe/0x30 [ 4.145945] ? ksmbd_smb2_check_message+0xeb2/0x24c0 [ 4.145948] ? smb2_tree_disconnect+0x31c/0x480 [ 4.145951] handle_ksmbd_work+0x40f/0x1080 [ 4.145953] process_one_work+0x5fa/0xef0 [ 4.145962] ? assign_work+0x122/0x3e0 [ 4.145964] worker_thread+0x54b/0xf70 [ 4.145967] ? __pfx_worker_thread+0x10/0x10 [ 4.145970] kthread+0x346/0x470 [ 4.145976] ? recalc_sigpending+0x19b/0x230 [ 4.145980] ? __pfx_kthread+0x10/0x10 [ 4.145984] ret_from_fork+0x4fb/0x6c0 [ 4.145992] ? __pfx_ret_from_fork+0x10

Affected

74 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.19.10-1 (forky)linux 6.19.10-1 (forky)
linuxlinux
linuxlinux
linuxlinux>= 5.15.121 < 5.15.2035.15.203
linuxlinux>= 5005bcb4219156f1bf7587b185080ec1da08518e < 806f13752652216db0c309392b4db3e64eeed4f2806f13752652216db0c309392b4db3e64eeed4f2
linuxlinux>= 5005bcb4219156f1bf7587b185080ec1da08518e < c742b46a153d3ff95ff0825ab1950c87b9e14470c742b46a153d3ff95ff0825ab1950c87b9e14470
linuxlinux>= 5005bcb4219156f1bf7587b185080ec1da08518e < 7f7468fd2a7554cea91b7d430335a3dbf01dcc097f7468fd2a7554cea91b7d430335a3dbf01dcc09
linuxlinux>= 5005bcb4219156f1bf7587b185080ec1da08518e < a5929c2020ce54e1dcbd1078c0f30b8aaf73c105a5929c2020ce54e1dcbd1078c0f30b8aaf73c105
linuxlinux>= 5005bcb4219156f1bf7587b185080ec1da08518e < c33615f995aee80657b9fdfbc4ee7f49c2bd733dc33615f995aee80657b9fdfbc4ee7f49c2bd733d
linuxlinux>= 6.1.36 < 6.1.1676.1.167
linuxlinux>= 6.3.10 < 6.46.4
linuxlinux>= 854156d12caa9d36de1cf5f084591c7686cc8a9d < eae0dc86f71e6f3294c0cd7ffc05039258d243afeae0dc86f71e6f3294c0cd7ffc05039258d243af
linuxlinux>= eb947403518ea3d93f6d89264bb1f5416bb0c7d0 < d08417981155883068b7260d9500ca306a03edacd08417981155883068b7260d9500ca306a03edac
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.19.10-16.19.10-1
linuxlinux_kernel>= 5.15.121 < 5.15.2035.15.203
linuxlinux_kernel>= 6.1.36 < 6.1.1676.1.167
linuxlinux_kernel>= 6.13 < 6.18.206.18.20
linuxlinux_kernel>= 6.19 < 6.19.106.19.10
linuxlinux_kernel>= 6.3.10 < 6.46.4
linuxlinux_kernel>= 6.4.1 < 6.6.1306.6.130
linuxlinux_kernel>= 6.7 < 6.12.786.12.78
ubuntulinux
ubuntulinux-aws

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_ubuntu8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.