Memory leak in Linux kernel - CVE-2026-90163
Published: September 19, 2026
Vulnerability details
The vulnerability allows a local privileged user to cause a denial of service through resource exhaustion.
The vulnerability exists due to improper resource cleanup in the KSMBD server module initialization error-unwind path when a later module initializer fails. A local privileged user can trigger KSMBD server module initialization that encounters a later initializer failure to cause a denial of service through resource exhaustion.