CVE-2026-53383 (GCVE-0-2026-53383)
Vulnerability from cvelistv5
Published
2026-07-19 11:59
Modified
2026-08-17 04:50
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: reject non-VALID session in compound request branch
smb2_check_user_session() takes a shortcut for any operation that is not
the first in a COMPOUND request: it reuses work->sess (the session bound by
the first operation) and validates only the SessionId, then returns
"valid". It never re-checks work->sess->state == SMB2_SESSION_VALID, and a
SessionId of 0xFFFFFFFFFFFFFFFF (ULLONG_MAX, the MS-SMB2 related-operation
value) skips even the id comparison. The standalone path
(ksmbd_session_lookup_all() plus the SESSION_SETUP state machine) does
enforce the VALID state; the compound branch bypasses all of it.
A SESSION_SETUP carrying only an NTLM Type-1 (NtLmNegotiate) blob publishes
a fresh SMB2_SESSION_IN_PROGRESS session whose sess->user is still NULL
(->user is assigned later, by ntlm_authenticate()). Used as operation 1 of
a COMPOUND with operation 2 = TREE_CONNECT (related, SessionId=ULLONG_MAX,
\\host\IPC$), the tree-connect then runs on that IN_PROGRESS session and
reaches ksmbd_ipc_tree_connect_request(), which dereferences
user_name(sess->user) with sess->user == NULL (transport_ipc.c:687/701/704)
-> remote NULL-pointer dereference and a kernel Oops that wedges the ksmbd
worker for all clients.
Reject any non-first compound operation that lands on a session which is
not SMB2_SESSION_VALID, mirroring the validity the standalone lookup path
enforces. SESSION_SETUP itself legitimately runs on an IN_PROGRESS session,
but it is never carried as a non-first compound operation, so multi-leg
authentication is unaffected by this check.
References
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: eb947403518ea3d93f6d89264bb1f5416bb0c7d0 Version: 854156d12caa9d36de1cf5f084591c7686cc8a9d Version: 5005bcb4219156f1bf7587b185080ec1da08518e Version: 5005bcb4219156f1bf7587b185080ec1da08518e Version: 5005bcb4219156f1bf7587b185080ec1da08518e Version: 5005bcb4219156f1bf7587b185080ec1da08518e Version: 5005bcb4219156f1bf7587b185080ec1da08518e Version: 5005bcb4219156f1bf7587b185080ec1da08518e Version: d1066c1b3663401cd23c0d6e60cdae750ce00c0f Version: 5.15.121 ≤ Version: 6.1.36 ≤ Version: 6.3.10 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/smb/server/smb2pdu.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "25ff12b82a376ff5c4583102a63d2456a6b9ebb9",
"status": "affected",
"version": "eb947403518ea3d93f6d89264bb1f5416bb0c7d0",
"versionType": "git"
},
{
"lessThan": "fc578523a72cb8b329d32070b95898e81613cc3f",
"status": "affected",
"version": "854156d12caa9d36de1cf5f084591c7686cc8a9d",
"versionType": "git"
},
{
"lessThan": "d2bbbb6c55812220fee5d801c275cc267ea3cbeb",
"status": "affected",
"version": "5005bcb4219156f1bf7587b185080ec1da08518e",
"versionType": "git"
},
{
"lessThan": "8f0302fb691537d33ec8f668565257ea9d340ffe",
"status": "affected",
"version": "5005bcb4219156f1bf7587b185080ec1da08518e",
"versionType": "git"
},
{
"lessThan": "7cad3ceaf679c55bc9946685dacafce78ce6b51a",
"status": "affected",
"version": "5005bcb4219156f1bf7587b185080ec1da08518e",
"versionType": "git"
},
{
"lessThan": "06e1f05a1dbe8bbd054c0927b17fc0a61cc8bef7",
"status": "affected",
"version": "5005bcb4219156f1bf7587b185080ec1da08518e",
"versionType": "git"
},
{
"lessThan": "5f983b864d3d473ac533b2f4f44a1bbe5dcbccf4",
"status": "affected",
"version": "5005bcb4219156f1bf7587b185080ec1da08518e",
"versionType": "git"
},
{
"lessThan": "609ca17d869d04ba249e32cdcbf13c0b1c66f43c",
"status": "affected",
"version": "5005bcb4219156f1bf7587b185080ec1da08518e",
"versionType": "git"
},
{
"status": "affected",
"version": "d1066c1b3663401cd23c0d6e60cdae750ce00c0f",
"versionType": "git"
},
{
"lessThan": "5.15.211",
"status": "affected",
"version": "5.15.121",
"versionType": "semver"
},
{
"lessThan": "6.1.177",
"status": "affected",
"version": "6.1.36",
"versionType": "semver"
},
{
"lessThan": "6.4",
"status": "affected",
"version": "6.3.10",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/smb/server/smb2pdu.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.4"
},
{
"lessThan": "6.4",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.211",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.177",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.144",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.95",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.37",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.0.*",
"status": "unaffected",
"version": "7.0.14",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.2",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.211",
"versionStartIncluding": "5.15.121",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.177",
"versionStartIncluding": "6.1.36",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.144",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.95",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.37",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.14",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.2",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "6.3.10",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: reject non-VALID session in compound request branch\n\nsmb2_check_user_session() takes a shortcut for any operation that is not\nthe first in a COMPOUND request: it reuses work-\u003esess (the session bound by\nthe first operation) and validates only the SessionId, then returns\n\"valid\". It never re-checks work-\u003esess-\u003estate == SMB2_SESSION_VALID, and a\nSessionId of 0xFFFFFFFFFFFFFFFF (ULLONG_MAX, the MS-SMB2 related-operation\nvalue) skips even the id comparison. The standalone path\n(ksmbd_session_lookup_all() plus the SESSION_SETUP state machine) does\nenforce the VALID state; the compound branch bypasses all of it.\n\nA SESSION_SETUP carrying only an NTLM Type-1 (NtLmNegotiate) blob publishes\na fresh SMB2_SESSION_IN_PROGRESS session whose sess-\u003euser is still NULL\n(-\u003euser is assigned later, by ntlm_authenticate()). Used as operation 1 of\na COMPOUND with operation 2 = TREE_CONNECT (related, SessionId=ULLONG_MAX,\n\\\\host\\IPC$), the tree-connect then runs on that IN_PROGRESS session and\nreaches ksmbd_ipc_tree_connect_request(), which dereferences\nuser_name(sess-\u003euser) with sess-\u003euser == NULL (transport_ipc.c:687/701/704)\n-\u003e remote NULL-pointer dereference and a kernel Oops that wedges the ksmbd\nworker for all clients.\n\nReject any non-first compound operation that lands on a session which is\nnot SMB2_SESSION_VALID, mirroring the validity the standalone lookup path\nenforces. SESSION_SETUP itself legitimately runs on an IN_PROGRESS session,\nbut it is never carried as a non-first compound operation, so multi-leg\nauthentication is unaffected by this check."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The bug is in ksmbd\u0027s SMB2 compound-request handler, reachable by any remote attacker who can send crafted SMB2 packets to TCP port 445 on a host running the in-kernel SMB server.\nAC:L - An attacker can reliably trigger the bug by sending a compound SMB2 request with SESSION_SETUP (NTLM Type-1 only) as the first operation and TREE_CONNECT (SessionId=0xFFFFFFFFFFFFFFFF, \\\\host\\IPC$) as the second; no special timing, memory layout, or victim state is required.\nPR:N - Exploitation requires only network access to ksmbd during the SMB2 authentication handshake, before sess-\u003euser is assigned; no Linux local account, capability, or prior authenticated OS session is needed.\nUI:N - No victim user action (opening files, mounting shares, clicking links) is required; the attacker triggers the crash solely by sending malicious SMB2 protocol traffic.\nS:U - The impact is a kernel oops and ksmbd worker disruption within the kernel/SMB server security authority; it does not cross a VM, container, or IOMMU boundary.\nC:N - The failure is a NULL pointer dereference on sess-\u003euser in ksmbd_ipc_tree_connect_request() when user_name(sess-\u003euser) is called with sess-\u003euser == NULL; this is a pure crash with no information disclosure.\nI:N - The bug causes a NULL pointer dereference only; there is no memory corruption, arbitrary write, or code-execution primitive\u2014only a kernel fault.\nA:H - The NULL dereference causes a kernel oops that wedges the shared ksmbd-io workqueue worker, denying SMB service to all clients connected through that worker and potentially panicking the host if panic_on_oops is enabled."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:50:33.785Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/25ff12b82a376ff5c4583102a63d2456a6b9ebb9"
},
{
"url": "https://git.kernel.org/stable/c/fc578523a72cb8b329d32070b95898e81613cc3f"
},
{
"url": "https://git.kernel.org/stable/c/d2bbbb6c55812220fee5d801c275cc267ea3cbeb"
},
{
"url": "https://git.kernel.org/stable/c/8f0302fb691537d33ec8f668565257ea9d340ffe"
},
{
"url": "https://git.kernel.org/stable/c/7cad3ceaf679c55bc9946685dacafce78ce6b51a"
},
{
"url": "https://git.kernel.org/stable/c/06e1f05a1dbe8bbd054c0927b17fc0a61cc8bef7"
},
{
"url": "https://git.kernel.org/stable/c/5f983b864d3d473ac533b2f4f44a1bbe5dcbccf4"
},
{
"url": "https://git.kernel.org/stable/c/609ca17d869d04ba249e32cdcbf13c0b1c66f43c"
}
],
"title": "ksmbd: reject non-VALID session in compound request branch",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-53383",
"datePublished": "2026-07-19T11:59:31.616Z",
"dateReserved": "2026-06-09T07:44:35.401Z",
"dateUpdated": "2026-08-17T04:50:33.785Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
Loading…
Loading…
Sightings
| Author | Source | Type | Date |
|---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
- Confirmed: The vulnerability is confirmed from an analyst perspective.
- Published Proof of Concept: A public proof of concept is available for this vulnerability.
- Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
- Patched: This vulnerability was successfully patched by the user reporting the sighting.
- Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
- Not confirmed: The user expresses doubt about the veracity of the vulnerability.
- Not patched: This vulnerability was not successfully patched by the user reporting the sighting.
Loading…
Loading…