External risk intelligence

Linux Kernel ksmbd Use-After-Free in Oplock Break Notification

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-80926

This vulnerability affects ksmbd, a Linux kernel SMB server. While SMB is commonly used in internal networks for file sharing and is rarely exposed directly to the public internet by design, it is occasionally misconfigured or exposed in specific deployments, making network reachability possible but not typical for a standard edge service.

Use After Free

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified and resolved in the Linux kernel's ksmbd component, which handles file sharing. This issue could allow an authenticated client to potentially access sensitive information or disrupt operations by exploiting a use-after-free flaw.

  • A Linux kernel file-sharing flaw is now fixed.
  • Key concern is confirming relevance and exposure.
  • Understand potential impact on our Linux systems.

Attack Path

How an attacker could exploit the issue

An authenticated client with a durable oplock can trigger a use-after-free vulnerability in the Linux kernel's ksmbd component. This occurs when a break notification races with the disconnection of a durable handle, leading to a freed connection being resurrected and then accessed. This condition can allow an attacker to crash the system or potentially execute arbitrary code.

  • Network access required.
  • Triggered by oplock break notification race.
  • Risk of system crash or code execution.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability in the Linux kernel's SMB server (ksmbd) could allow an authenticated client holding a specific type of lock to cause a use-after-free condition. This may occur when the server is handling an oplock break notification while a connection is being torn down.

  • File access, system data at risk.
  • Race condition during connection teardown.
  • Potential for system instability or crashes.

Operational Fix

Recommended remediation, mitigation, and detection steps

This critical vulnerability in the Linux kernel's ksmbd component likely requires action from infrastructure or platform teams responsible for managing the kernel and SMB services. The first practical step is to identify all systems running ksmbd, determine their network exposure and business criticality, and locate the accountable system owner. Remediation planning should then proceed based on this risk assessment.

  • Kernel and SMB platform teams own resolution.
  • Verify ksmbd instances and network exposure.
  • Plan remediation based on criticality.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is ksmbd in the Linux kernel?

ksmbd is a kernel-based file server that implements the SMB protocol directly within the Linux kernel. It allows systems to share files and printers with other computers across a network. Unlike user-space alternatives, it is designed for high-performance file sharing by avoiding frequent context switching between the kernel and user space when processing file requests.

What does use-after-free mean for CVE-2026-80926?

A use-after-free is a memory management flaw where a program continues to use a pointer after the memory it references has been cleared or deleted. In this case, the system mistakenly tries to access a network connection object that was already freed during a connection shutdown. This can lead to unpredictable behavior, such as system crashes or potentially allowing an attacker to manipulate memory to execute unintended commands.

How is this ksmbd flaw triggered?

The vulnerability is triggered by a race condition during an oplock break notification. An attacker must be an authenticated client holding a durable batch oplock—a specific type of file-locking mechanism. It does not occur through simple network requests; it requires a precise overlap where a break notification is processed at the same time the server is disconnecting the durable handle.

How do I know if my system is at risk according to Halo Surface Signal?

Halo Surface Signal indicates that while ksmbd is primarily used on internal networks, you should prioritize systems where this service is reachable over the network. Although SMB is rarely intended for public internet exposure, misconfigurations can inadvertently make these services accessible. Identifying if your ksmbd instance is exposed to broader network segments is a key step in assessing your specific risk level.

What should I do if I run systems with ksmbd?

The immediate priority is to locate all servers or devices in your environment that utilize the ksmbd component. Once identified, evaluate their network reachability and business importance to determine the urgency of your response. Coordinate with your platform or infrastructure team to review available security updates for your Linux kernel distribution, as they will be responsible for applying the necessary fixes.

References