Linux Kernel ksmbd Durable Handle Reconnection Owner Validation Vulnerability

Vulnerability

A vulnerability in the Linux kernel's ksmbd component allows authenticated users to hijack orphaned durable handles by predicting or brute-forcing persistent IDs. This issue arises because ksmbd does not verify if the user reconnecting to a durable handle is the same one who originally opened the file. The vulnerability is present in the Linux kernel stable tree.

Impact

Exploitation of this vulnerability allows for unauthorized hijacking of durable handles, potentially leading to unauthorized access or manipulation of files.

Reproduction

To reproduce this vulnerability, an authenticated user can predict or brute-force the persistent ID of an orphaned durable handle. Once the ID is successfully guessed, the user can reconnect to the handle, bypassing the original owner's permissions.

Remediation

Users should update to the latest version of the Linux kernel where this vulnerability has been addressed.

Added: May 1, 2026, 2:24 PM
Updated: May 1, 2026, 2:24 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
1.3
exploitability
3.9
remediation
7.7
relevance
7.2
threat
4.8
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.