Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

CVE-2026-72422

ksmbd: fix use-after-free of conn->preauth_info in concurrent SMB2 NEGOTIATE
Back to all
CVE

CVE-2026-72422

ksmbd: fix use-after-free of conn->preauth_info in concurrent SMB2 NEGOTIATE

In the Linux kernel, the following vulnerability has been resolved:

ksmbd: fix use-after-free of conn->preauth_info in concurrent SMB2 NEGOTIATE

conn->preauth_info is shared connection state (struct

preauthintegrityinfo, kmalloc-96) that is allocated and freed by the

SMB2 NEGOTIATE handler and read by the response send path.

smb2handlenegotiate() allocates conn->preauth_info, and on a

deassemblenegcontexts() failure kfrees it and sets it to NULL. Both the

allocation and the free/NULL happen under ksmbdconnlock(conn) (the

connection srv_mutex), which is held across the whole handler body.

The response send path smb3preauthhash_rsp(), called from the send:

block of _handleksmbdwork(), reads conn->preauthinfo and dereferences

conn->preauthinfo->PreauthHashValue (via

ksmbdgenpreauthintegrityhash()) without taking conn_lock. When a

client drives two SMB2 NEGOTIATE requests on the same connection, one

worker can free conn->preauth_info on the failing-negotiate path while a

concurrent send-path worker is reading it, producing a slab

use-after-free read (KASAN-confirmed).

The send-path read tested conn->preauth_info for NULL but raced with the

free that occurs between the NULL check and the dereference, so the NULL

guard alone does not close the window.

Serialize the NEGOTIATE-branch read in smb3preauthhash_rsp() under

ksmbdconnlock(conn) and re-check conn->preauth_info inside the lock.

Because the negotiate handler holds conn_lock across its kfree + NULL

assignment, a reader that also takes conn_lock either runs fully before

the allocation or fully after the NULL store, and can never observe the

freed-but-not-yet-NULLed pointer. ksmbdgenpreauthintegrityhash()

takes no locks itself (it only computes a SHA-512 over the buffer), so

no lock-ordering inversion is introduced, and conn_lock is a sleepable

mutex which is safe on this send path (it already performs network I/O).

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
9.8
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
0
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
-

Related Resources

No items found.

References

https://git.kernel.org/stable/c/0c054227479ed7e36ebccb3a558bc0ef698264f6, https://git.kernel.org/stable/c/16a1ecf39c217e3d164bd32ef2a4f650abc067fa, https://git.kernel.org/stable/c/1c89da3baa2b1f269178afa87dc30479b8535776, https://git.kernel.org/stable/c/7470511d085af1c7a043a60e53d52b512d5a10b1, https://git.kernel.org/stable/c/77bb0bbfcc4e777ca653174689e5e363f8ee63d1, https://git.kernel.org/stable/c/c7bef84740d1d57848c74f6f5b996606e43ea4fe, https://git.kernel.org/stable/c/d0a469122e7bf8338fec1949fb1e8e1290ed8caa, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72422.json, https://nvd.nist.gov/vuln/detail/CVE-2026-72422, https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Severity

9.8

CVSS Score
0
10

Basic Information

Base CVSS
9.8
EPSS Probability
0.0066%
EPSS Percentile
0.48922%
Introduced Version
dd4e4c811898410e6a3ae3b63207b7c542860907,aa7253c2393f6dcd6a1468b0792f6da76edad917,0,5.15.61,5.18.18,5.19.2,5.16.0,6.0.0,6.2.0,6.7.0,6.13.0
Fix Available
c7bef84740d1d57848c74f6f5b996606e43ea4fe,0c054227479ed7e36ebccb3a558bc0ef698264f6,5.15.212,5.19,5.20,6.1.178,6.6.145,6.12.97,6.18.40,7.1.5,6.1.180-1,6.12.100-1

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading