CVE-2026-53046
A critical use‑after‑free bug in the Linux kernel’s ksmbd component can crash the system when Qualcomm crypto engines are used. The flaw occurs when the kernel incorrectly handles asynchronous crypto requests, freeing memory before the hardware operation completes. An attacker could trigger a crash, potentially leading to denial of service.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Linux kernel (all versions before the ksmbd patch) – Linux system administrators and users running older kernel versions are affected.
Real-world impact
An attacker could crash the system, causing a denial of service and potentially disrupting services that rely on the kernel’s SMB server.
Why this severity
The CVSS score of 9.8 reflects that the vulnerability can be exploited remotely without authentication, leading to a complete loss of confidentiality, integrity, and availability. The attack requires no user interaction and can crash the system, making it a critical threat.
What to do about it
- 01Upgrade the Linux kernel to a version that includes the ksmbd patch that fixes the use‑after‑free vulnerability.
- 02Reboot the system to load the new kernel.
NVD-referenced vendor advisory
Timeline
- Jun 24, 2026 · Jun 24, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 21, 2026 · 13d agoAdvisory updatedThe NVD record was last revised.
- Jul 21, 2026 · 13d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- git.kernel.org/stable/c/3e298897f41c61450c…patch
- git.kernel.org/stable/c/57b47231055b431ed0…patch
- git.kernel.org/stable/c/7164b3953cefd540e7…patch
- git.kernel.org/stable/c/8ef183216feaa24b66…patch
- git.kernel.org/stable/c/8fcefe840fa8c14ce6…patch
- git.kernel.org/stable/c/b46aa129fa2807bfe1…patch
- git.kernel.org/stable/c/cc2da381875d4a6702…patch