CVE-2026-90152: Linux

EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: smb/server: fix session leak in ksmbd_session_register() See the procedure below: smb2_sess_setup ksmbd_smb2_session_create __session_create atomic_set(&sess->refcnt, 2) hash_add(sessions_table, &sess->hlist, sess->id) ksmbd_session_register xa_store(&conn->sessions, sess->id, sess) // fail ksmbd_user_session_put atomic_dec(&sess->refcnt) // refcnt is 1, session is not freed Remove the session from sessions_table and drop its table reference if xa_store() fails.

Affected products

  • Linux Linux: from 5.15.145, before 5.16 (fixed in 5.16); from 6.1.29, before 6.2 (fixed in 6.2); from 6.2.16, before 6.3 (fixed in 6.3); from 6.3.2, before 6.4 (fixed in 6.4); from 6.4, before 6.12.110 (fixed in 6.12.110); from 6.13, before 6.18.52 (fixed in 6.18.52); …

Published 2026-09-17. Last modified 2026-09-17.