CVE-2026-52911
published 2026-06-21CVE-2026-52911: In the Linux kernel, the following vulnerability has been resolved: ksmbd: scope conn->binding slowpath to bound sessions only When the binding SESSION_SETUP…
PriorityP349high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.36%
28.4th percentile
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: scope conn->binding slowpath to bound sessions only
When the binding SESSION_SETUP sets conn->binding = true, the flag stays
set after the call so that the global session lookup in
ksmbd_session_lookup_all() can find the session, which was not added to
conn->sessions. Because the flag is connection-wide, the global lookup
path will also resolve any other session by id if asked.
Tighten the global lookup so that the returned session must have this
connection registered in its channel xarray (sess->ksmbd_chann_list).
The channel entry is installed by the existing binding_session path in
ntlm_authenticate()/krb5_authenticate() when a SESSION_SETUP completes
successfully, so this condition is a strict equivalent of "this
connection has been accepted as a channel of this session". Connections
that have not bound to a given session cannot reach it via the global
table.
The existing conn->binding gate for entering the slowpath is preserved
so that non-binding connections keep the fast-path-only behavior, and
the session->state check is unchanged.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| linux | linux | — | — |
| linux | linux | >= f5a544e3bab78142207e0242d22442db85ba1eff < e74c00c6af428a39e564cdc5bd3a3648c6d8de87 | e74c00c6af428a39e564cdc5bd3a3648c6d8de87 |
| linux | linux | >= f5a544e3bab78142207e0242d22442db85ba1eff < e3a93ce6e25757b8f375e38b8f91e1d9da4edc1a | e3a93ce6e25757b8f375e38b8f91e1d9da4edc1a |
| linux | linux | >= f5a544e3bab78142207e0242d22442db85ba1eff < 1ff46c9915c1cbf454db58a8cb87f7cac818e6a6 | 1ff46c9915c1cbf454db58a8cb87f7cac818e6a6 |
| linux | linux | >= f5a544e3bab78142207e0242d22442db85ba1eff < 974c1c224e85549dc3459f3bb2255bbbdd2b9372 | 974c1c224e85549dc3459f3bb2255bbbdd2b9372 |
| linux | linux | >= f5a544e3bab78142207e0242d22442db85ba1eff < 2cc8a4db633b10715450b291c1343859a4b2c509 | 2cc8a4db633b10715450b291c1343859a4b2c509 |
| linux | linux | >= f5a544e3bab78142207e0242d22442db85ba1eff < 1e2bec062c5c9ec282636715166056d0998d746d | 1e2bec062c5c9ec282636715166056d0998d746d |
| linux | linux | >= f5a544e3bab78142207e0242d22442db85ba1eff < b0da97c034b6107d14e537e212d4ce8b22109a58 | b0da97c034b6107d14e537e212d4ce8b22109a58 |
| linux | linux_kernel | >= 5.15 < 5.15.209 | 5.15.209 |
| linux | linux_kernel | >= 5.16 < 6.1.175 | 6.1.175 |
| linux | linux_kernel | >= 6.13 < 6.18.33 | 6.18.33 |
| linux | linux_kernel | >= 6.19 < 7.0.10 | 7.0.10 |
| linux | linux_kernel | >= 6.2 < 6.6.141 | 6.6.141 |
| linux | linux_kernel | >= 6.7 < 6.12.91 | 6.12.91 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
In the Linux kernel, the following vulnerability has been resolved: ksmbd: scope conn->binding slowpath to bound sessions only When the binding SESSION_SETUP sets conn->binding = true, the flag stay
ghsa_unreviewed·2026-06-21
CVE-2026-52911 In the Linux kernel, the following vulnerability has been resolved: ksmbd: scope conn->binding slowpath to bound sessions only When the binding SESSION_SETUP sets conn->binding = true, the flag stay
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: scope conn->binding slowpath to bound sessions only
When the binding SESSION_SETUP sets conn->binding = true, the flag stays
set after the call so that the global session lookup in
ksmbd_session_lookup_all() can find the session, which was not added to
conn->sessions. Because the flag is connection-wide, the global lookup
path will also resolve any other session by id if asked.
Tighten the global lookup so that the returned session must have this
connection registered in its channel xarray (sess->ksmbd_chann_list).
The channel entry is installed by the existing binding_session path in
ntlm_authenticate()/krb5_authenticate() when a SESSION_SETUP completes
successfully, so this condition is a strict equivalent of "
VulDB
Linux Kernel up to 7.0.9 ksmbd ksmbd_session_lookup_all state issue (EUVD-2026-38148 / Nessus ID 321869)
vuldb·2026-06-21
CVE-2026-52911 [CRITICAL] Linux Kernel up to 7.0.9 ksmbd ksmbd_session_lookup_all state issue (EUVD-2026-38148 / Nessus ID 321869)
A vulnerability classified as critical has been found in Linux Kernel up to 7.0.9. The affected element is the function ksmbd_session_lookup_all of the component ksmbd. Performing a manipulation results in state issue.
This vulnerability is cataloged as CVE-2026-52911. The attack must originate from the local network. There is no exploit available.
It is recommended to upgrade the affected component.
Red Hat
kernel: ksmbd: scope conn->binding slowpath to bound sessions only
vendor_redhat·2026-06-21
CVE-2026-52911 CWE-488 kernel: ksmbd: scope conn->binding slowpath to bound sessions only
kernel: ksmbd: scope conn->binding slowpath to bound sessions only
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: scope conn->binding slowpath to bound sessions only
When the binding SESSION_SETUP sets conn->binding = true, the flag stays
set after the call so that the global session lookup in
ksmbd_session_lookup_all() can find the session, which was not added to
conn->sessions. Because the flag is connection-wide, the global lookup
path will also resolve any other session by id if asked.
Tighten the global lookup so that the returned session must have this
connection registered in its channel xarray (sess->ksmbd_chann_list).
The channel entry is installed by the existing binding_session path in
ntlm_authenticate()/krb5_authenticate() when a SESSION_SETUP comp
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/1e2bec062c5c9ec282636715166056d0998d746dhttps://git.kernel.org/stable/c/1ff46c9915c1cbf454db58a8cb87f7cac818e6a6https://git.kernel.org/stable/c/2cc8a4db633b10715450b291c1343859a4b2c509https://git.kernel.org/stable/c/974c1c224e85549dc3459f3bb2255bbbdd2b9372https://git.kernel.org/stable/c/b0da97c034b6107d14e537e212d4ce8b22109a58https://git.kernel.org/stable/c/e3a93ce6e25757b8f375e38b8f91e1d9da4edc1ahttps://git.kernel.org/stable/c/e74c00c6af428a39e564cdc5bd3a3648c6d8de87
2026-06-21
Published