In the Linux kernel, the following vulnerability has been resolved:
ksmbd: unset conn->binding on failed binding request
When a multichannel SMB2_SESSION_SETUP request with
SMB2_SESSION_REQ_FLAG_BINDING fails ksmbd sets conn->binding = true
but never clears it on the error path. This leaves the connection in
a binding state where all subsequent ksmbd_session_lookup_all() calls
fall back to the global sessions table. This fix it by clearing
conn->binding = false in the error path.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2026-04-06 08:16
Updated : 2026-07-24 22:10
NVD link : CVE-2026-31409
Mitre link : CVE-2026-31409
CVE.ORG link : CVE-2026-31409
JSON object : View
Products Affected
linux
- linux_kernel
CWE
