CVE-2026-53198

Description

A flaw was found in ksmbd, a Linux kernel module that provides an in-kernel SMB server. An authenticated SMB client can trigger a use-after-free vulnerability by sending a double SMB2_CANCEL request for the same asynchronous operation. This can lead to memory corruption, potentially allowing an attacker to cause a denial of service or execute arbitrary code.

Understanding the Weakness (CWE)

Availability,Integrity

Technical Impact: DoS: Crash, Exit, or Restart

Frequently Asked Questions

Want to get errata notifications? Sign up here.