Linux hwe edge: In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix durable reconnect error path file lifetime After a durable reconnect… (CVE-2026-64016)
A vulnerability in the Linux kernel's ksmbd component related to durable reconnect handling has been resolved. The issue involves improper cleanup of file objects after a durable reconnect succeeds, potentially leading to use-after-free conditions due to session-unaware file closure. This could impact confidentiality, integrity, and availability of the system. The vulnerability has a high CVSS score of 9.8, indicating critical severity. No affected versions are explicitly stated. No known exploits in the wild have been reported. The vulnerability is not related to a cloud service. Patch status is not confirmed from the provided data.
AI Analysis
Technical Summary
The vulnerability in the Linux kernel ksmbd module concerns the handling of durable reconnect error paths. After a durable reconnect succeeds, the same ksmbd_file is republished in the session volatile-id table. If an error occurs later in smb2_open(), cleanup calls ksmbd_fd_put() and then unconditionally calls ksmbd_put_durable_fd() on the same file object. The final close operation is not session-aware and may free the file object without removing its volatile-id entry, leading to a potential use-after-free or stale reference. Earlier reconnect failures do not exhibit this issue as they use a different cleanup path. This flaw could allow attackers to affect system confidentiality, integrity, and availability.
Potential Impact
Successful exploitation could lead to use-after-free conditions in the ksmbd file handling, potentially causing system instability, crashes, or unauthorized access to kernel memory. The CVSS 3.1 score of 9.8 reflects critical impact on confidentiality, integrity, and availability. No known exploits in the wild have been reported.
Mitigation Recommendations
Patch status is not confirmed from the provided information. Users should monitor official Linux kernel advisories and apply updates when available to address this vulnerability. Since this is a kernel-level issue, updating to a fixed kernel version is the recommended remediation once released.
Linux hwe edge: In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix durable reconnect error path file lifetime After a durable reconnect… (CVE-2026-64016)
Description
A vulnerability in the Linux kernel's ksmbd component related to durable reconnect handling has been resolved. The issue involves improper cleanup of file objects after a durable reconnect succeeds, potentially leading to use-after-free conditions due to session-unaware file closure. This could impact confidentiality, integrity, and availability of the system. The vulnerability has a high CVSS score of 9.8, indicating critical severity. No affected versions are explicitly stated. No known exploits in the wild have been reported. The vulnerability is not related to a cloud service. Patch status is not confirmed from the provided data.
CVSS v3.1
Score 9.8critical
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in the Linux kernel ksmbd module concerns the handling of durable reconnect error paths. After a durable reconnect succeeds, the same ksmbd_file is republished in the session volatile-id table. If an error occurs later in smb2_open(), cleanup calls ksmbd_fd_put() and then unconditionally calls ksmbd_put_durable_fd() on the same file object. The final close operation is not session-aware and may free the file object without removing its volatile-id entry, leading to a potential use-after-free or stale reference. Earlier reconnect failures do not exhibit this issue as they use a different cleanup path. This flaw could allow attackers to affect system confidentiality, integrity, and availability.
Potential Impact
Successful exploitation could lead to use-after-free conditions in the ksmbd file handling, potentially causing system instability, crashes, or unauthorized access to kernel memory. The CVSS 3.1 score of 9.8 reflects critical impact on confidentiality, integrity, and availability. No known exploits in the wild have been reported.
Mitigation Recommendations
Patch status is not confirmed from the provided information. Users should monitor official Linux kernel advisories and apply updates when available to address this vulnerability. Since this is a kernel-level issue, updating to a fixed kernel version is the recommended remediation once released.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-w63r-7cfm-vm57
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-64016"]
- Ecosystems
- []
- Database Specific Severity
- null
- Cvss Version
- 3.1
Threat ID: 6a5d27a92a4a8d598912d23b
Added to database: 07/19/2026, 19:38:17 UTC
Last enriched: 07/31/2026, 23:46:27 UTC
Last updated: 08/30/2026, 10:52:10 UTC
Views: 53
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.