Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-98115— ksmbd: safely drain sessions during logoff

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Linux 内核中,已修复以下漏洞: ksmbd:在注销期间安全地排空会话 SMB3 多通道允许针对同一会话的请求在多个连接上并行运行。在释放共享会话对象之前,必须等待与该会话关联的所有通道完成。 延后的字节范围锁仍被视为正在运行的请求,仅在文件关闭时才会被唤醒。在排空过程中唤醒被阻塞的锁时,不得发布或修改其文件对象。同步取消请求必须通过调用其取消回调来唤醒挂起的操作,而 CHANGE_NOTIFY 完成事件仅适用于异步路径。 将会话拆除过程与通道注册及先前会话清理进行序列化,并使用原子工作态转换,确保 LOG

CVSS 8.8 · High EPSS 0.35% · P26

Affected Version Matrix 10

VendorProduct Version RangeStatus
Linux Linux 76e98a158b207771a6c9a0de0a60522a446a3447< a7e6df0bb92642bee4431b2b85c69ada1e463b21 affected
76e98a158b207771a6c9a0de0a60522a446a3447< d12168084c8c1b6d883c8eca5853929ac5136a9e affected
118fd997612d1efc94a86c307c6c6d659ebe29fc affected
c1e55020534c4aafbc38d8f5c4583ff30755ac18 affected
6.6.48< 6.7 affected
6.10.7< 6.11 affected
6.11 affected
< 6.11 unaffected
… +2 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-98115

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
ksmbd: safely drain sessions during logoff
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: ksmbd: safely drain sessions during logoff SMB3 multichannel allows requests for one session to run on multiple connections. Wait for all channels bound to a session before freeing shared session objects. A deferred byte-range lock remains counted as a running request and only wakes when its file closes. Wake blocked locks during the drain without unpublishing or modifying their file objects. Synchronous CANCEL requests must invoke their cancellation callback to wake pending operations, while CHANGE_NOTIFY completion remains specific to the asynchronous path. Serialize session teardown with channel registration and previous-session cleanup, and use atomic work-state transitions so LOGOFF, CANCEL, and connection teardown invoke cancellation callbacks only once.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux 76e98a158b207771a6c9a0de0a60522a446a3447 ~ a7e6df0bb92642bee4431b2b85c69ada1e463b21 -
Linux Linux 6.11 -

II. Public POCs for CVE-2026-98115

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-98115

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-98115 (2)

Same Patch Batch · Linux · 2026-09-25 · 372 CVEs total

CVE-2026-100075 9.8 CRITICAL RDMA/srpt: Fix srpt_alloc_rw_ctxs() unwind counters
CVE-2026-97555 8.8 HIGH smb: client: fix heap overflow in DACL owner/group rewrite
CVE-2026-97527 8.8 HIGH scsi: qla2xxx: Serialize NVMe unsol ctx list with a per-fcport lock
CVE-2026-97528 8.8 HIGH scsi: qla2xxx: Unlink NVMe unsol ctx before freeing on LS reject error
CVE-2026-97957 8.8 HIGH net: hinic: fix mailbox segment buffer overflow
CVE-2026-97525 8.2 HIGH x86/mm/pat: Allocate split page tables as kernel page tables
CVE-2026-97570 8.1 HIGH bnxt_en: Bound SW TPA IDs to prevent crashes
CVE-2026-98130 8.1 HIGH sctp: fix a TOCTOU race in SCTP_CMD_TIMER_START
CVE-2026-98070 8.1 HIGH net/rds: acquire RDS_IN_XMIT in rds_tcp_reset_callbacks()
CVE-2026-98069 8.1 HIGH net/rds: acquire the fastpath locks in rds_conn_shutdown()
CVE-2026-97573 8.1 HIGH bnxt_en: Handle buffer allocation failure in bnxt_rx_ring_reset()
CVE-2026-97940 7.8 HIGH ipv6: fix fib6 walker UAF on seq stop
CVE-2026-98112 7.8 HIGH ksmbd: fix listener task lifetime on netdev events
CVE-2026-97941 7.8 HIGH mm/slab: take n->list_lock in __slab_try_return_freelist() to avoid race
CVE-2026-98122 7.8 HIGH vxlan: mdb: Fix use-after-free in vxlan_mdb_remote_src_del()
CVE-2026-97612 7.8 HIGH net: mpls: clear inner_protocol when the last label is popped
CVE-2026-97991 7.8 HIGH vdpa_sim_blk: reject out-of-range sector starts
CVE-2026-97611 7.8 HIGH net: openvswitch: fix use-after-free of the flow table mask array
CVE-2026-98002 7.8 HIGH iommu/amd: Fix ineffective error check in nested domain allocation
CVE-2026-98073 7.8 HIGH net: Remove conflicting altnames for dying netns in __dev_change_net_namespace().

Showing top 20 of 372 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-98115

No comments yet


Leave a comment