CVE-2026-53046
Gravedad CVSS v3.1:
CRÍTICA
Tipo:
CWE-416
Utilización después de liberación
Fecha de publicación:
24/06/2026
Última modificación:
21/07/2026
Descripción
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
ksmbd: fix use-after-free from async crypto on Qualcomm crypto engine<br />
<br />
ksmbd_crypt_message() sets a NULL completion callback on AEAD requests<br />
and does not handle the -EINPROGRESS return code from async hardware<br />
crypto engines like the Qualcomm Crypto Engine (QCE). When QCE returns<br />
-EINPROGRESS, ksmbd treats it as an error and immediately frees the<br />
request while the hardware DMA operation is still in flight. The DMA<br />
completion callback then dereferences freed memory, causing a NULL<br />
pointer crash:<br />
<br />
pc : qce_skcipher_done+0x24/0x174<br />
lr : vchan_complete+0x230/0x27c<br />
...<br />
el1h_64_irq+0x68/0x6c<br />
ksmbd_free_work_struct+0x20/0x118 [ksmbd]<br />
ksmbd_exit_file_cache+0x694/0xa4c [ksmbd]<br />
<br />
Use the standard crypto_wait_req() pattern with crypto_req_done() as<br />
the completion callback, matching the approach used by the SMB client<br />
in fs/smb/client/smb2ops.c. This properly handles both synchronous<br />
engines (immediate return) and async engines (-EINPROGRESS followed<br />
by callback notification).
Impacto
Puntuación base 3.x
9.80
Gravedad 3.x
CRÍTICA
Productos y versiones vulnerables
| CPE | Desde | Hasta |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.15 (incluyendo) | 5.15.209 (excluyendo) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.16 (incluyendo) | 6.1.175 (excluyendo) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.2 (incluyendo) | 6.6.141 (excluyendo) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.7 (incluyendo) | 6.12.91 (excluyendo) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.13 (incluyendo) | 6.18.33 (excluyendo) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.19 (incluyendo) | 7.0.10 (excluyendo) |
Para consultar la lista completa de nombres de CPE con productos y versiones, ver esta página
Referencias a soluciones, herramientas e información
- https://git.kernel.org/stable/c/3e298897f41c61450c2e7a4f457e8b2485eb35b3
- https://git.kernel.org/stable/c/57b47231055b431ed0a1a55f33cac32981564405
- https://git.kernel.org/stable/c/7164b3953cefd540e7ebca828c793bc6869cfbc4
- https://git.kernel.org/stable/c/8ef183216feaa24b66b940510d8b68f680eb56e9
- https://git.kernel.org/stable/c/8fcefe840fa8c14ce667768e5b043286ac3bbcbe
- https://git.kernel.org/stable/c/b46aa129fa2807bfe1545fe74d9295d53c51520b
- https://git.kernel.org/stable/c/cc2da381875d4a67026e4c8feb3dba51a2a2d1bc



