Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-53010: Linux kernel ksmbd SMB2 reconnect causes file descriptor leak

CVE-2026-53010
Summary

A bug in the Linux kernel's ksmbd SMB2 reconnect process could cause a file descriptor to be deleted too early, leading to data loss. This issue has been fixed in a recent update. Update your Linux kernel to the latest version to ensure you have this fix.

Original title
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in smb2_open during durable reconnect In smb2_open, the call to ksmbd_put_durable_fd(fp) drops the re...
Original description
In the Linux kernel, the following vulnerability has been resolved:

ksmbd: fix use-after-free in smb2_open during durable reconnect

In smb2_open, the call to ksmbd_put_durable_fd(fp) drops the reference
to the durable file descriptor early during the durable reconnect
process. If an error occurs subsequently (eg, ksmbd_iov_pin_rsp fails)
or a scavenger accesses the file, it leads to a use-after-free when
accessing fp properties (eg fp->create_time).

Move the single put to the end of the function below err_out2 so fp
stays valid until smb2_open returns.
nvd CVSS3.1 9.8
Published: 24 Jun 2026 · Updated: 23 Jul 2026 · First seen: 28 Jun 2026