CVE-2026-68130

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
10/08/2026
Last modified:
19/08/2026

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> ksmbd: defer destroy_previous_session() until after NTLM authentication<br /> <br /> In ntlm_authenticate(), destroy_previous_session() is called using a<br /> user pointer resolved from the client-supplied NTLM blob username field<br /> before the NTLMv2 response is validated. An authenticated attacker can<br /> set the NTLM blob username to match a victim account and set<br /> PreviousSessionId to the victim&amp;#39;s session ID; destroy_previous_session()<br /> destroys the victim&amp;#39;s session while ksmbd_decode_ntlmssp_auth_blob()<br /> subsequently rejects the request with -EPERM.<br /> <br /> Move destroy_previous_session() and the prev_id assignment to after<br /> ksmbd_decode_ntlmssp_auth_blob() returns success and use sess-&gt;user<br /> rather than the pre-authentication lookup result. This matches the<br /> ordering already used by krb5_authenticate(), where<br /> destroy_previous_session() is called only after<br /> ksmbd_krb5_authenticate() returns success.

Impact