CVE-2026-90152
Received Received - Intake

BaseFortify

Vulnerability report for CVE-2026-90152, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-17

Last updated on: 2026-09-17

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: smb/server: fix session leak in ksmbd_session_register() See the procedure below: smb2_sess_setup ksmbd_smb2_session_create __session_create atomic_set(&sess->refcnt, 2) hash_add(sessions_table, &sess->hlist, sess->id) ksmbd_session_register xa_store(&conn->sessions, sess->id, sess) // fail ksmbd_user_session_put atomic_dec(&sess->refcnt) // refcnt is 1, session is not freed Remove the session from sessions_table and drop its table reference if xa_store() fails.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-17
Last Modified
2026-09-17
Generated
2026-10-10
EPSS Evaluated
2026-10-09
NVD

Affected Vendors & Products

Showing 13 associated CPEs
Vendor Product Version / Range
Linux Linux f5c779b7ddbda30866cf2a27c63e34158f858c73
Linux Linux f5c779b7ddbda30866cf2a27c63e34158f858c73
Linux Linux f5c779b7ddbda30866cf2a27c63e34158f858c73
Linux Linux f5c779b7ddbda30866cf2a27c63e34158f858c73
Linux Linux 708c304b583d789957399dd8237f212cf8ad1e4d
Linux Linux f623f627ad2b1dc215ab3b0df53fb05cfd3a1c3b
Linux Linux d270631c21e68fb8016d6e231d022d7023a2df6f
Linux Linux 02f41d88f15d6b7d523e52cc3f87488f57e9265b
Linux Linux 5.15.145
Linux Linux 6.1.29
Linux Linux 6.2.16
Linux Linux 6.3.2
Linux Linux 6.4

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
AI Quick Actions have not been generated yet.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-90152. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart