Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

DEBIAN-CVE-2026-89788

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix tree connection use-after-free in smb2_tree_connect() ksmbd_tree_conn_connect() publishes a new tree connection in sess...
Back to all
CVE

DEBIAN-CVE-2026-89788

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix tree connection use-after-free in smb2_tree_connect() ksmbd_tree_conn_connect() publishes a new tree connection in sess...

In the Linux kernel, the following vulnerability has been resolved:  ksmbd: fix tree connection use-after-free in smb2treeconnect()  ksmbdtreeconnconnect() publishes a new tree connection in sess->treeconns with a single reference and returns its pointer to smb2treeconnect(). The handler continues to initialize the object and build the response after publication. A concurrent session logoff can erase the connection and drop that reference, freeing the object while the handler still uses it.  BUG: KASAN: slab-use-after-free in smb2treeconnect+0xe3d/0xf90   smb2treeconnect (fs/smb/server/smb2pdu.c:2872)   handleksmbdwork   processonework   workerthread   kthread  After xastore() succeeds, take a second reference before releasing treeconnslock. The original reference belongs to the xarray entry and the second belongs to the creating smb2treeconnect() handler.  Keep the references balanced in every path:  - On normal exit or an error after publication, smb2treeconnect()   drops its creator reference. Error cleanup also calls   ksmbdtreeconndisconnect(), which drops the xarray reference only if   it removes the exact entry. - SMB2 TREEDISCONNECT uses the same helper to remove the entry and drop   its xarray reference. The request's existing lookup reference remains   owned by the request and is released by the existing cleanup. - Session LOGOFF removes each entry and drops its xarray reference. If   it wins the race, later cleanup sees that the entry is gone and does   not drop that reference again.  To enforce this ownership, claim the disconnected state and erase the exact entry atomically under treeconnslock. This guarantees one drop for the xarray reference and one drop by each in-flight user, regardless of which teardown path wins. If logoff removes the entry before initialization completes, fail the connect instead of marking the detached object TREE_CONNECTED.

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
-
C
H
U
0
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
-

Related Resources

No items found.

References

https://security-tracker.debian.org/tracker/CVE-2026-89788

Severity

9.8

CVSS Score
0
10

Basic Information

Base CVSS
9.8
EPSS Probability
0%
EPSS Percentile
0%
Introduced Version
0
Fix Available
7.2.6-1

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading