External risk intelligence

Linux Kernel SMBdirect Use-After-Free Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-90173

The vulnerability exists in Linux kernel-level RDMA/SMBDirect completion queue management. This is a low-level kernel component responsible for internal hardware/protocol communication, not a network-exposed service, API, or web application. It is functionally isolated from direct external interaction.

Use After Free

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This vulnerability in the Linux kernel concerns how certain network communication components manage their completion queues. If a specific sequence of events occurs during network operations, it can lead to system instability. The main concern is to confirm if this low-level kernel functionality is relevant to your specific systems.

  • It's a kernel issue with network communication.
  • Leadership should remember it if systems use specific networking.
  • Confirm relevance and exposure of this low-level function.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by triggering a race condition within the Linux kernel's handling of network connections, specifically involving the destruction of completion queues used for communication. This could occur when a late completion signal from a network provider conflicts with the destruction of these queues, leading to memory corruption.

  • Entry condition: Attacker triggers a late network completion.
  • Trigger point: Destroying a connection with outstanding work.
  • Resulting risk: System instability and potential data corruption.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability in the Linux kernel's SMBDirect component could lead to a system crash when a late completion is posted after a queue has been freed. This happens due to improper handling of completion queues during connection destruction, potentially causing a use-after-free error.

  • Kernel memory corruption.
  • Late completion posts trigger crash.
  • System instability or denial of service.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in the Linux kernel's SMBDirect component affects systems using RDMA (Remote Direct Memory Access) over SMB. The immediate action is to identify all systems utilizing SMBDirect, assess their exposure and criticality, and then determine the appropriate remediation plan, which may involve coordinating with infrastructure or platform teams.

  • Linux kernel and infrastructure teams own remediation.
  • Verify SMBDirect and RDMA usage and exposure.
  • Plan and schedule kernel updates or mitigations.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the SMBDirect component in the Linux kernel?

SMBDirect is a protocol implementation within the Linux kernel that enables Remote Direct Memory Access (RDMA). It allows systems to transfer data directly between the memory of two computers over a network, bypassing the operating system's CPU and kernel overhead to achieve higher performance and lower latency for storage traffic.

What does the CVE-2026-90173 vulnerability mean?

This is a use-after-free vulnerability, which is a memory management defect. It occurs when a system attempts to access a piece of memory after it has been deallocated. In this specific case, the kernel improperly frees completion queues used for network operations. If a delayed signal arrives after the queue is freed, the system accesses invalid memory, causing instability.

How is this vulnerability triggered?

An attacker needs to force a race condition during the destruction of an SMBDirect connection. The flaw is triggered when a late network completion signal is posted after the system has already freed the associated completion queue. If the system is not using SMBDirect with RDMA, or if connections are not being destroyed while work is pending, this specific bug will not be triggered.

Is this vulnerability relevant to my environment?

Halo Surface Signal indicates that while this is a critical kernel issue, it is very unlikely to be reachable from the internet. This bug resides in low-level kernel infrastructure, not in network-exposed APIs or web applications. Relevance depends entirely on whether your systems are configured to use SMBDirect over RDMA for internal network communication.

What should I do to address CVE-2026-90173?

First, inventory your infrastructure to identify servers actively using SMBDirect and RDMA protocols. Since this requires a kernel-level modification, you should work with your platform or Linux administration teams to track official kernel updates from your distribution provider and schedule the necessary patches during your standard maintenance windows.

References