Critical kernel UAF in ksmbd with SMB exposure; core infra across Linux servers, high risk.
CVE-2026-43376
Critical Linux ksmbd UAF in oplock_info; deferred freeing fixes memory safety.
Is CVE-2026-43376 being exploited?
Not confirmed. CVE-2026-43376 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.44% probability of exploitation in the next 30 days.
How severe is CVE-2026-43376?
CVE-2026-43376 is rated Critical with a CVSS score of 9.8. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-43376?
Yes. A fix has been recorded for CVE-2026-43376. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-43376 affect?
CVE-2026-43376 affects Linux kernel (ksmbd). Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-43376?
Update to patched kernel/ksmbd version
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Kernel use-after-free may crash or allow code execution via ksmbd SMB path.
Patch when possible
- affected>= 296cb5457cc6f4a754c4ae29855f8a253d52bcc6 and < 302fef75512b2c8329a3f5efab1ae7ba2562387a
- affected>= d54ab1520d43e95f9b2e22d7a05fc9614192e5a5 and < 08aa9f3c8cf4d0bee44df540dfe34e8d64069f2c
- affected>= 18b4fac5ef17f77fed9417d22210ceafd6525fc7 and < 1d6abf145615dbfe267ce3b0a271f95e3780e18e
- affected>= 18b4fac5ef17f77fed9417d22210ceafd6525fc7 and < ce8507ee82c888126d8e7565e27c016308d24cde
- affected>= 18b4fac5ef17f77fed9417d22210ceafd6525fc7 and < 1dfd062caa165ec9d7ee0823087930f3ab8a6294
- affectedd73686367ad68534257cd88a36ca3c52cb8b81d8
- affected>= 6.6.88 and < 6.6.130
- affected>= 6.12.25 and < 6.12.78
- affected>= 6.14.4 and < 6.15
- affected6.15
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.