IM
IronMonkey Threat Research

CVE-2026-23228 MEDIUM

Published: 2026-02-18 | Last Modified: 2026-06-02 | Status: Modified

Description

In the Linux kernel, the following vulnerability has been resolved: smb: server: fix leak of active_num_conn in ksmbd_tcp_new_connection() On kthread_run() failure in ksmbd_tcp_new_connection(), the transport is freed via free_transport(), which does not decrement active_num_conn, leaking this counter. Replace free_transport() with ksmbd_tcp_disconnect().

Additional Descriptions (1)

Se ha resuelto la siguiente vulnerabilidad en el kernel de Linux: smb: servidor: corregir fuga de active_num_conn en ksmbd_tcp_new_connection() En caso de fallo de kthread_run() en ksmbd_tcp_new_connection(), se libera el transporte a través de free_transport(), lo que no decrementa active_num_conn, fugando este contador. Reemplazar free_transport() con ksmbd_tcp_disconnect().

CVSS Metrics

Base Score: 5.5 (MEDIUM)

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack VectorLOCAL
Attack ComplexityLOW
Privileges RequiredLOW
User InteractionNONE
ScopeUNCHANGED
Confidentiality ImpactNONE
Integrity ImpactNONE
Availability ImpactHIGH

Source: [email protected]

Type: Primary

Exploitability Score: 1.8

Impact Score: 3.6

Weaknesses

Source Type Description
[email protected] Primary
en CWE-401

Affected Products

Vendor Product Version Update Type
linux linux_kernel * <built-in method update of dict object at 0x7f7638068dc0> Operating System
linux linux_kernel * <built-in method update of dict object at 0x7f764032f400> Operating System
linux linux_kernel * <built-in method update of dict object at 0x7f7637fd7d80> Operating System
linux linux_kernel * <built-in method update of dict object at 0x7f76394cf480> Operating System
linux linux_kernel * <built-in method update of dict object at 0x7f760078aec0> Operating System
linux linux_kernel * <built-in method update of dict object at 0x7f7600788c00> Operating System
linux linux_kernel 6.2 <built-in method update of dict object at 0x7f76026fb8c0> Operating System
linux linux_kernel 6.2 <built-in method update of dict object at 0x7f763a7e1280> Operating System
linux linux_kernel 6.2 <built-in method update of dict object at 0x7f763a7e1840> Operating System
linux linux_kernel 6.2 <built-in method update of dict object at 0x7f7600789600> Operating System

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:6.2:-:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:6.2:rc6:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:6.2:rc7:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:6.2:rc8:*:*:*:*:*:*

References

Notification
Message here