External risk intelligence

Linux Kernel ksmbd Rebinds Incorrect Oplocks After Durable Reconnect

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-89635

The vulnerability exists in ksmbd, a Linux kernel SMB server. While SMB is a network protocol, it is typically restricted to internal local networks or VPNs. Direct exposure of SMB services to the public internet is a security misconfiguration and is not a standard or recommended deployment pattern for this service.

Use After Free

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability has been identified in the Linux kernel's ksmbd component, which handles SMB network file sharing. This issue could potentially allow unauthorized access or manipulation of data under specific conditions involving multiple connected sessions and file access.

  • An issue exists in how Linux kernel file sharing handles reconnecting sessions.
  • Leadership should remember this if their organization uses Linux for file sharing.
  • Confirming relevance and exposure is the primary leadership concern.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by leveraging an authenticated session against a specific file share configuration. The attack involves two separate sessions simultaneously holding durable handles to the same file. When both sessions disconnect and one reconnects, it can incorrectly adopt the other session's oplock. This incorrect adoption, followed by subsequent operations on the freed session, can lead to a crash.

  • Requires authenticated access to a share.
  • Two sessions with durable handles on the same file.
  • Risk of system crash due to use-after-free.

Live Threat

Current exploitation, exposure, and threat context

When supported by the advisory, authenticated sessions against an SMB share could lead to a use-after-free vulnerability. This may occur when two sessions hold durable handles on the same file, disconnect, and then one session reconnects, potentially adopting the other's oplock.

  • In-memory file system state could be corrupted.
  • A reconnecting session may adopt another's oplock.
  • System instability or crashes may occur.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Linux kernel's ksmbd component is affected by a vulnerability that could lead to a use-after-free condition. This issue is most likely to impact infrastructure or platform teams managing Linux servers that are configured to use the ksmbd SMB server. The immediate first step is to identify all Linux systems running ksmbd, confirm their exposure and criticality, and then engage the relevant system owner to plan remediation.

  • Identify Linux systems running ksmbd.
  • Verify SMB service exposure and business criticality.
  • Coordinate with system owners for remediation planning.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is ksmbd in the Linux kernel?

ksmbd is an in-kernel SMB server module designed to provide high-performance file sharing capabilities within Linux environments. It allows Linux systems to act as file servers, enabling Windows and other clients to access shared folders and files across a network using the SMB/CIFS protocol.

How does CVE-2026-89635 function as a vulnerability?

This vulnerability is a use-after-free weakness caused by incorrect session management. When a session performs a durable reconnect, the server can mistakenly bind a session to the wrong file lock (oplock) held by another user. When that original session is later destroyed, the system attempts to access stale memory associated with the prematurely freed session, leading to memory corruption or a system crash.

Do I need multiple sessions to trigger this bug?

Yes. This flaw is triggered specifically when two distinct sessions hold durable handles on the same file, both disconnect, and one then reconnects. It does not occur with simple, single-user access. The logic error only arises during the complex state transitions where handles from different sessions become entangled during the reconnection process.

Is my system at risk if I use ksmbd?

Risk depends on your deployment and access controls. According to Halo Surface Signal, this service is typically restricted to internal networks or VPNs, making internet exposure unlikely. However, because the vulnerability requires an authenticated session, internal users or compromised accounts with permission to access file shares are the primary threat actors who could initiate this failure.

How should I respond to CVE-2026-89635?

Begin by auditing your infrastructure to identify which Linux servers are running the ksmbd kernel module. Prioritize systems that host sensitive file shares or support high-traffic multi-user environments. Once identified, consult your Linux distribution's security advisories to track the availability of kernel updates that resolve this issue, and plan a maintenance window to apply the patched kernel.

References