SB20260815308 - Use-after-free in Linux kernel smb server
Published: August 15, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Use-after-free (CVE-ID: CVE-2026-72422)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a use-after-free in smb3_preauth_hash_rsp() when processing concurrent SMB2 NEGOTIATE requests on the same connection. A remote attacker can send concurrent SMB2 NEGOTIATE requests that trigger a race and dereference freed memory to cause a denial of service.
The issue is a race between the SMB2 NEGOTIATE handler and the response send path, where a NULL check can be bypassed by concurrent freeing of conn->preauth_info before dereference.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/0c054227479ed7e36ebccb3a558bc0ef698264f6
- https://git.kernel.org/stable/c/16a1ecf39c217e3d164bd32ef2a4f650abc067fa
- https://git.kernel.org/stable/c/1c89da3baa2b1f269178afa87dc30479b8535776
- https://git.kernel.org/stable/c/7470511d085af1c7a043a60e53d52b512d5a10b1
- https://git.kernel.org/stable/c/77bb0bbfcc4e777ca653174689e5e363f8ee63d1
- https://git.kernel.org/stable/c/c7bef84740d1d57848c74f6f5b996606e43ea4fe
- https://git.kernel.org/stable/c/d0a469122e7bf8338fec1949fb1e8e1290ed8caa