CVE-2026-23228

Source
https://cve.org/CVERecord?id=CVE-2026-23228
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-23228.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-23228
Downstream
Published
2026-02-18T14:53:31.882Z
Modified
2026-03-13T04:06:48.810677Z
Summary
smb: server: fix leak of active_num_conn in ksmbd_tcp_new_connection()
Details

In the Linux kernel, the following vulnerability has been resolved:

smb: server: fix leak of activenumconn in ksmbdtcpnew_connection()

On kthreadrun() failure in ksmbdtcpnewconnection(), the transport is freed via freetransport(), which does not decrement activenum_conn, leaking this counter.

Replace freetransport() with ksmbdtcp_disconnect().

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/23xxx/CVE-2026-23228.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
4210c3555db4b38bade92331b153e583261f05f9
Fixed
6dd2645cf080a75be31fa66063c7332b291f46f0
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
d5d7847e57ac69fa99c18b363a34419bcdb5a281
Fixed
7ddd69cd1338c6197e1b6b19cec60d99c8633e4f
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
0d0d4680db22eda1eea785c47bbf66a9b33a8b16
Fixed
787769c8cc50416af7b8b1a36e6bcd6aaa7680aa
Fixed
baf664fc90a6139a39a58333e4aaa390c10d45dc
Fixed
cd25e0d809531a67e9dd53b19012d27d2b13425f
Fixed
599271110c35f6b16e2e4e45b9fbd47ed378c982
Fixed
77ffbcac4e569566d0092d5f22627dfc0896b553

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-23228.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.15.201
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.164
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.125
Fixed
6.12.72
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.18.11
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.19.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-23228.json"