CVE-2026-74494
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: reject repeated SMB2 NEGOTIATE requests
Unauthenticated client can send multiple successful SMB2 NEGOTIATE requests on one connection before SESSION_SETUP. While the connection is in KSMBD_SESS_NEED_SETUP, smb2_handle_negotiate() accepts another SMB3.1.1 NEGOTIATE and overwrites conn->preauth_info with a new allocation. Only the final allocation is freed when the connection is released, leaking one object for every additional successful request.
A repeated SMB2 NEGOTIATE after a dialect has been selected is a protocol violation. MS-SMB2 section 3.3.5.4 requires the server to disconnect without replying in this case.
Leer descripción completaMostrar menos
Set the connection exiting when rejecting the request, in addition to suppressing the response.
Reject SMB2 NEGOTIATE unless the connection is new or is waiting for the SMB2 NEGOTIATE that follows an SMB1 multi-protocol negotiate. Serialize both SMB1 and SMB2 negotiation paths under conn->srv_mutex, since they update connection-wide dialect and negotiation state.
Move the locking contract to ksmbd_smb_negotiate_common(), where the state and dialect are selected, and add ksmbd_conn_new() for consistent state access.
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.21%
- Percentil entre todas las CVEs puntuadas: 11
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/0b1390cf2b6b91723b37c0909dd123f7a5eba1a7
- https://git.kernel.org/stable/c/7e02cb30e8a1f5fc78cb10b220b06020e36d0bbe
- https://git.kernel.org/stable/c/7fb8dbeb3f2868ae836ca12311d89aed16fc2927
- https://git.kernel.org/stable/c/81e21cb7bd1479bb5238e0004a7e0110452c610b
- https://git.kernel.org/stable/c/a60b5da05e318d9a364dbac38c347c7f24e625e7
- https://git.kernel.org/stable/c/cb469993b3a61a72653770856d37af616d72d05f
- https://git.kernel.org/stable/c/fd6a6c43f96b40a08a22ff62f08d194a49741c8a
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-74494",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9",
"lessThan": "0b1390cf2b6b91723b37c0909dd123f7a5eba1a7",
"versionType": "git"
},
{
"status": "affected",
"version": "e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9",
"lessThan": "fd6a6c43f96b40a08a22ff62f08d194a49741c8a",
"versionType": "git"
},
{
"status": "affected",
"version": "e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9",
"lessThan": "81e21cb7bd1479bb5238e0004a7e0110452c610b",
"versionType": "git"
},
{
"status": "affected",
"version": "e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9",
"lessThan": "7fb8dbeb3f2868ae836ca12311d89aed16fc2927",
"versionType": "git"
},
{
"status": "affected",
"version": "e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9",
"lessThan": "a60b5da05e318d9a364dbac38c347c7f24e625e7",
"versionType": "git"
},
{
"status": "affected",
"version": "e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9",
"lessThan": "7e02cb30e8a1f5fc78cb10b220b06020e36d0bbe",
"versionType": "git"
},
{
"status": "affected",
"version": "e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9",
"lessThan": "cb469993b3a61a72653770856d37af616d72d05f",
"versionType": "git"
}
],
"programFiles": [
"fs/smb/server/connection.h",
"fs/smb/server/smb2pdu.c",
"fs/smb/server/smb_common.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "5.15"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "5.15",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.153",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.105",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver",
"lessThanOrEqual": "7.1.*"
},
{
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"fs/smb/server/connection.h",
"fs/smb/server/smb2pdu.c",
"fs/smb/server/smb_common.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-08-15T13:17:54.353",
"references": [
{
"url": "https://git.kernel.org/stable/c/0b1390cf2b6b91723b37c0909dd123f7a5eba1a7",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/7e02cb30e8a1f5fc78cb10b220b06020e36d0bbe",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/7fb8dbeb3f2868ae836ca12311d89aed16fc2927",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/81e21cb7bd1479bb5238e0004a7e0110452c610b",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/a60b5da05e318d9a364dbac38c347c7f24e625e7",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/cb469993b3a61a72653770856d37af616d72d05f",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/fd6a6c43f96b40a08a22ff62f08d194a49741c8a",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: reject repeated SMB2 NEGOTIATE requests\n\nUnauthenticated client can send multiple successful SMB2 NEGOTIATE\nrequests on one connection before SESSION_SETUP. While the connection is\nin KSMBD_SESS_NEED_SETUP, smb2_handle_negotiate() accepts another\nSMB3.1.1 NEGOTIATE and overwrites conn->preauth_info with a new allocation.\nOnly the final allocation is freed when the connection is released, leaking\none object for every additional successful request.\n\nA repeated SMB2 NEGOTIATE after a dialect has been selected is a protocol\nviolation. MS-SMB2 section 3.3.5.4 requires the server to disconnect\nwithout replying in this case. Set the connection exiting when rejecting\nthe request, in addition to suppressing the response.\n\nReject SMB2 NEGOTIATE unless the connection is new or is waiting for the\nSMB2 NEGOTIATE that follows an SMB1 multi-protocol negotiate. Serialize\nboth SMB1 and SMB2 negotiation paths under conn->srv_mutex, since they\nupdate connection-wide dialect and negotiation state.\n\nMove the locking contract to ksmbd_smb_negotiate_common(), where the state\nand dialect are selected, and add ksmbd_conn_new() for consistent state\naccess."
}
],
"lastModified": "2026-08-23T13:16:44.870",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}