CVE-2026-23282: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.1% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix oops due to uninitialised var in smb2_unlink() If SMB2_open_init() or SMB2_close_init() fails (e.g. reconnect), the iovs set @rqst will be left uninitialised, hence calling SMB2_open_free(), SMB2_close_free() or smb2_set_related() on them will oops. Fix this by initialising @close_iov and @open_iov before setting them in @rqst.

Affected products

  • Linux Linux Kernel: from 6.17.1, before 6.18.17 (fixed in 6.18.17); from 6.19, before 6.19.7 (fixed in 6.19.7); version 6.17 only; version 7.0 only

Published 2026-03-25. Last modified 2026-06-17.