Null Pointer Dereference Vulnerability in Linux Kernel's ksmbd Component
CVE-2026-64141

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
19 July 2026

What is CVE-2026-64141?

A vulnerability in the ksmbd component of the Linux kernel allows for a null pointer dereference during session teardown handling, leading to potential system crashes. Specifically, the issue arises when a stale operation information structure remains linked during session logoff and a subsequent connection attempt with the same ClientGuid is made. If a new SMB2 CREATE request is made with a lease context on a different inode, the kernel may panic due to an attempt to dereference a null connection pointer. Proper handling in concurrent session checks is crucial to mitigate this issue.

Affected Version(s)

Linux 8df4bcdb0a4232192b2445256c39b787d58ef14d

Linux c8efcc786146a951091588e5fa7e3c754850cb3c < 0836081b394ca074d1b910f2b990ff7b4b4404c7

Linux c8efcc786146a951091588e5fa7e3c754850cb3c

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.