-

CVE-2026-68130

ksmbd: defer destroy_previous_session() until after NTLM authentication

In the Linux kernel, the following vulnerability has been resolved:

ksmbd: defer destroy_previous_session() until after NTLM authentication

In ntlm_authenticate(), destroy_previous_session() is called using a
user pointer resolved from the client-supplied NTLM blob username field
before the NTLMv2 response is validated. An authenticated attacker can
set the NTLM blob username to match a victim account and set
PreviousSessionId to the victim's session ID; destroy_previous_session()
destroys the victim's session while ksmbd_decode_ntlmssp_auth_blob()
subsequently rejects the request with -EPERM.

Move destroy_previous_session() and the prev_id assignment to after
ksmbd_decode_ntlmssp_auth_blob() returns success and use sess->user
rather than the pre-authentication lookup result. This matches the
ordering already used by krb5_authenticate(), where
destroy_previous_session() is called only after
ksmbd_krb5_authenticate() returns success.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9
Version < ab0230257ebdf48b07eaa679a8c92bc842fe3498
Status affected
Version e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9
Version < 370b0ec8822b69c9073265e16b7daaa8201c9a4f
Status affected
Version e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9
Version < 5c833074b549e5db125436a6f681af682261f785
Status affected
Version e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9
Version < 243f1614ef2aca2d62a744575f1c24b07cd42757
Status affected
Version e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9
Version < 18705cace0619fd2123737dcd028147774f38181
Status affected
Version e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9
Version < 0ff12308c8a6c16ab68f0a487ffa93d69001dc18
Status affected
Version e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9
Version < c74801ee524f477c174a1899782b6c3b6918d407
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 5.15
Status affected
Version 0
Version < 5.15
Status unaffected
Version <= 5.15.*
Version 5.15.217
Status unaffected
Version <= 6.1.*
Version 6.1.183
Status unaffected
Version <= 6.6.*
Version 6.6.148
Status unaffected
Version <= 6.12.*
Version 6.12.101
Status unaffected
Version <= 6.18.*
Version 6.18.42
Status unaffected
Version <= 7.1.*
Version 7.1.6
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.22% 0.123
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/5c833074b549e5db125436a6f681af682261f785
https://git.kernel.org/stable/c/243f1614ef2aca2d62a744575f1c24b07cd42757
https://git.kernel.org/stable/c/18705cace0619fd2123737dcd028147774f38181
https://git.kernel.org/stable/c/0ff12308c8a6c16ab68f0a487ffa93d69001dc18
https://git.kernel.org/stable/c/c74801ee524f477c174a1899782b6c3b6918d407
https://git.kernel.org/stable/c/370b0ec8822b69c9073265e16b7daaa8201c9a4f
https://git.kernel.org/stable/c/ab0230257ebdf48b07eaa679a8c92bc842fe3498