CVE-2026-53010
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: fix use-after-free in smb2_open during durable reconnect
In smb2open, the call to ksmbdputdurablefd(fp) drops the reference
to the durable file descriptor early during the durable reconnect
process. If an error occurs subsequently (eg, ksmbdiovpin_rsp fails)
or a scavenger accesses the file, it leads to a use-after-free when
accessing fp properties (eg fp->create_time).
Move the single put to the end of the function below err_out2 so fp
stays valid until smb2_open returns.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://git.kernel.org/stable/c/1baff47b81f94f9231c91236aa511420d0e266b9, https://git.kernel.org/stable/c/97a0cd55283b4e63fd92804da91c8d9896adcad9, https://git.kernel.org/stable/c/ce2e164c1c51c3f7813b80f8c926836e896bcbb3, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/53xxx/CVE-2026-53010.json, https://nvd.nist.gov/vuln/detail/CVE-2026-53010, https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git