CVE-2026-53046

Severity CVSS v4.0:
Pending analysis
Type:
CWE-416 Use After Free
Publication date:
24/06/2026
Last modified:
21/07/2026

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> ksmbd: fix use-after-free from async crypto on Qualcomm crypto engine<br /> <br /> ksmbd_crypt_message() sets a NULL completion callback on AEAD requests<br /> and does not handle the -EINPROGRESS return code from async hardware<br /> crypto engines like the Qualcomm Crypto Engine (QCE). When QCE returns<br /> -EINPROGRESS, ksmbd treats it as an error and immediately frees the<br /> request while the hardware DMA operation is still in flight. The DMA<br /> completion callback then dereferences freed memory, causing a NULL<br /> pointer crash:<br /> <br /> pc : qce_skcipher_done+0x24/0x174<br /> lr : vchan_complete+0x230/0x27c<br /> ...<br /> el1h_64_irq+0x68/0x6c<br /> ksmbd_free_work_struct+0x20/0x118 [ksmbd]<br /> ksmbd_exit_file_cache+0x694/0xa4c [ksmbd]<br /> <br /> Use the standard crypto_wait_req() pattern with crypto_req_done() as<br /> the completion callback, matching the approach used by the SMB client<br /> in fs/smb/client/smb2ops.c. This properly handles both synchronous<br /> engines (immediate return) and async engines (-EINPROGRESS followed<br /> by callback notification).

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.15 (including) 5.15.209 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.16 (including) 6.1.175 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.2 (including) 6.6.141 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.7 (including) 6.12.91 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.13 (including) 6.18.33 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.19 (including) 7.0.10 (excluding)