This vulnerability in the Linux kernel's ksmbd SMB server implementation occurs when a failed multichannel SMB2_SESSION_SETUP request with the binding flag leaves the connection in an incorrect binding state. The flaw affects the ksmbd subsystem, which provides SMB protocol support in the Linux kernel and is commonly used in network-attached storage systems and server deployments. The vulnerability has minimal severity based on available metrics, with an EPSS score of 0.00013 and a FAUCET risk score of 27.0 out of 100, indicating low prevalence and impact. While specific CVSS vector information is not available, the root cause suggests this would require an authenticated attacker with network access to exploit, as it is triggered during SMB session binding operations. There is no current evidence of active exploitation, and the vulnerability is not included in CISA's Known Exploited Vulnerabilities catalog. The relatively low risk scores and inactive status suggest minimal community attention and available exploit code, indicating this remains a low-priority vulnerability despite being a logic error in session management that could potentially lead to authentication bypass or session hijacking under specific conditions.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.15, < 6.1.167CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.2, < 6.6.130CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.7, < 6.12.78CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.13, < 6.18.20CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.19, < 6.19.10CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Linux kernel (Azure CVM) vulnerabilities
Jul 24, 2026Linux kernel vulnerabilities
Jul 24, 2026Linux kernel (Azure CVM) vulnerabilities
Jul 24, 2026Linux kernel (Azure FIPS) vulnerabilities
Jul 24, 2026Linux kernel (Azure CVM) vulnerabilities
Jul 24, 2026Linux kernel (Azure) vulnerabilities
Jul 24, 2026Linux kernel (AWS) vulnerabilities
Jul 24, 2026Linux kernel (NVIDIA) vulnerabilities
Jul 23, 2026Linux kernel (Oracle) vulnerabilities
Jul 23, 2026Linux kernel vulnerabilities
Jul 23, 2026Linux kernel (NVIDIA Tegra) vulnerabilities
Jul 21, 2026Linux kernel vulnerabilities
Jul 21, 2026Linux kernel (GCP FIPS) vulnerabilities
Jul 21, 2026Linux kernel vulnerabilities
Jul 20, 2026