« Volver al listado

CVE-2026-90164

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

smb/server: abort initialization when proc setup fails

ksmbd_server_init() calls ksmbd_proc_init() before creating the remaining proc entries and server subsystems. ksmbd_proc_init() tears down partial state on a procfs or percpu_counter allocation failure, but returns void, so ksmbd_server_init() continues as if the counters were usable.

Once userspace starts the server, server_ctrl_handle_init() calls ksmbd_proc_reset(), which reaches percpu_counter_set() with a NULL per-CPU counters pointer on SMP systems. The later ksmbd_proc_create() calls also receive a NULL parent and may create entries in the /proc root; ksmbd_proc_cleanup() cannot remove those entries because ksmbd_proc_fs is NULL.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-90164",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "b38f99c1217ae04753340f0fdcd8f35bf56841dc",
              "lessThan": "fb4ba2bdfc1de8866e7c8e00df99f4b03ff42f09",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "b38f99c1217ae04753340f0fdcd8f35bf56841dc",
              "lessThan": "db97f3763727d652112ae70038d4e17b3ce277bb",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "fs/smb/server/misc.h",
            "fs/smb/server/proc.c",
            "fs/smb/server/server.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "7.0"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "7.0",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "7.2.6",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "fs/smb/server/misc.h",
            "fs/smb/server/proc.c",
            "fs/smb/server/server.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-17T17:17:09.747",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/db97f3763727d652112ae70038d4e17b3ce277bb",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/fb4ba2bdfc1de8866e7c8e00df99f4b03ff42f09",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmb/server: abort initialization when proc setup fails\n\nksmbd_server_init() calls ksmbd_proc_init() before creating the\nremaining proc entries and server subsystems. ksmbd_proc_init() tears\ndown partial state on a procfs or percpu_counter allocation failure,\nbut returns void, so ksmbd_server_init() continues as if the counters\nwere usable.\n\nOnce userspace starts the server, server_ctrl_handle_init() calls\nksmbd_proc_reset(), which reaches percpu_counter_set() with a NULL\nper-CPU counters pointer on SMP systems. The later ksmbd_proc_create()\ncalls also receive a NULL parent and may create entries in the /proc\nroot; ksmbd_proc_cleanup() cannot remove those entries because\nksmbd_proc_fs is NULL."
    }
  ],
  "lastModified": "2026-09-17T17:17:09.747",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}