Use-after-free in Linux kernel - CVE-2026-90168
Published: September 19, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to use-after-free in ksmbd deferred CHANGE_NOTIFY work when deferred notification work is released after connection teardown. A remote attacker can send a CHANGE_NOTIFY request and terminate the connection to cause a denial of service.
Exploitation requires a durable handle to outlive its connection.