Two Linux Kernel KSMBD Vulnerabilities Enable Remote Code Execution
Article Content
- •ZDI-26-693 requires authentication; ZDI-26-684 does not.
- •Both vulnerabilities allow remote code execution on Linux Kernel KSMBD.
- •Linux has issued updates to mitigate these vulnerabilities.
Two vulnerabilities in the Linux Kernel KSMBD have been disclosed, allowing remote attackers to execute arbitrary code. The first vulnerability (ZDI-26-693) requires authentication and affects systems with ksmbd enabled, while the second (ZDI-26-684) does not require authentication and targets systems with KSMBD enabled. Both vulnerabilities stem from improper locking mechanisms in the handling of specific objects, leading to potential code execution in the kernel context. Linux has issued updates to address these vulnerabilities. The vulnerabilities were reported to the vendor on different dates, with both advisories released on September 14, 2026. The lack of authentication in the second vulnerability raises its severity, as it could be exploited more easily. Organizations using affected Linux Kernel versions should prioritize applying the patches.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
Critical GitLab CVE-2026-85706 Exploited; Microsoft Issues Record 974 Patches A critical CVE-2026-85706 path-traversal vulnerability in GitLab (CVSS 10.0) was exploited in the wild just hours after its disclosure on September 12, 2026. Microsoft released its largest-ever patch batch, addressing 974 vulnerabilities, including several actively exploited Windows flaws. The GitLab flaw allows…