Use-after-free in Linux kernel - CVE-2026-72422
Published: August 15, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a use-after-free in smb3_preauth_hash_rsp() when processing concurrent SMB2 NEGOTIATE requests on the same connection. A remote attacker can send concurrent SMB2 NEGOTIATE requests that trigger a race and dereference freed memory to cause a denial of service.
The issue is a race between the SMB2 NEGOTIATE handler and the response send path, where a NULL check can be bypassed by concurrent freeing of conn->preauth_info before dereference.
Affected software
Ubuntu
linux (Ubuntu package)
linux-gcp (Ubuntu package)
How to mitigate CVE-2026-72422
linux (Ubuntu package) - addressed in versions 7.0.0-34.34, 7.0.0-34.34.1, 7.0.0-34.34~24.04.1, 7.0.0-1012.12~24.04.1, 7.0.0-1013.13, 7.0.0-1013.13~24.04.1, 7.0.0-1014.14, 7.0.0-1020.20
linux-gcp (Ubuntu package) - addressed in versions 7.0.0-1013.13, 7.0.0-1013.13~24.04.1, 7.0.0-1014.14
External References
- https://git.kernel.org/stable/c/0c054227479ed7e36ebccb3a558bc0ef698264f6
- https://git.kernel.org/stable/c/16a1ecf39c217e3d164bd32ef2a4f650abc067fa
- https://git.kernel.org/stable/c/1c89da3baa2b1f269178afa87dc30479b8535776
- https://git.kernel.org/stable/c/7470511d085af1c7a043a60e53d52b512d5a10b1
- https://git.kernel.org/stable/c/77bb0bbfcc4e777ca653174689e5e363f8ee63d1
- https://git.kernel.org/stable/c/c7bef84740d1d57848c74f6f5b996606e43ea4fe
- https://git.kernel.org/stable/c/d0a469122e7bf8338fec1949fb1e8e1290ed8caa