Skip to content
ThreatCluster

Two Linux Kernel KSMBD Vulnerabilities Enable Remote Code Execution

First seen 14 Sep 2026, 17:54 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 14, 2026 at 18:57 UTC
  • ZDI-26-693 requires authentication; ZDI-26-684 does not.
  • Both vulnerabilities allow remote code execution on Linux Kernel KSMBD.
  • Linux has issued updates to mitigate these vulnerabilities.

Two vulnerabilities in the Linux Kernel KSMBD have been disclosed, allowing remote attackers to execute arbitrary code. The first vulnerability (ZDI-26-693) requires authentication and affects systems with ksmbd enabled, while the second (ZDI-26-684) does not require authentication and targets systems with KSMBD enabled. Both vulnerabilities stem from improper locking mechanisms in the handling of specific objects, leading to potential code execution in the kernel context. Linux has issued updates to address these vulnerabilities. The vulnerabilities were reported to the vendor on different dates, with both advisories released on September 14, 2026. The lack of authentication in the second vulnerability raises its severity, as it could be exploited more easily. Organizations using affected Linux Kernel versions should prioritize applying the patches.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-03-30
ZDI-26-693 reported to vendor
The vulnerability was disclosed to Linux for remediation, affecting systems with ksmbd enabled.
Zerodayinitiative
2026-06-11
ZDI-26-684 reported to vendor
The second vulnerability was disclosed to Linux, impacting systems with KSMBD enabled.
Zerodayinitiative
2026-09-14
Coordinated public release of advisories
Both vulnerabilities were publicly disclosed, highlighting their potential risks.
Zerodayinitiative
2026-09-14
Advisory updated
Updates to advisories were made to provide further details on the vulnerabilities.
Zerodayinitiative

More articles in this cluster (3)