Kernel vulnerability in widely deployed Linux (ksmbd SMB server). Network-accessible, high-severity kernel corruption that can disrupt infrastructure.
CVE-2026-72422
ksmbd use-after-free in SMB2 NEGOTIATE enabling remote kernel compromise
Is CVE-2026-72422 being exploited?
Not confirmed. CVE-2026-72422 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.66% probability of exploitation in the next 30 days.
How severe is CVE-2026-72422?
CVE-2026-72422 is rated Critical with a CVSS score of 9.8. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-72422?
Yes. A fix has been recorded for CVE-2026-72422. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-72422 affect?
CVE-2026-72422 affects Linux kernel (ksmbd SMB server), Linux distributions shipping ksmbd, Servers running kernel SMB/CIFS features. Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-72422?
Apply vendor kernel patch or disable ksmbd/SMB kernel server until patched
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Remote attacker can trigger kernel use-after-free via SMB2 NEGOTIATE, causing memory corruption leading to crash, privilege escalation, or RCE.
Immediate action required
- affected>= dd4e4c811898410e6a3ae3b63207b7c542860907 and < c7bef84740d1d57848c74f6f5b996606e43ea4fe
- affected>= aa7253c2393f6dcd6a1468b0792f6da76edad917 and < d0a469122e7bf8338fec1949fb1e8e1290ed8caa
- affected>= aa7253c2393f6dcd6a1468b0792f6da76edad917 and < 7470511d085af1c7a043a60e53d52b512d5a10b1
- affected>= aa7253c2393f6dcd6a1468b0792f6da76edad917 and < 16a1ecf39c217e3d164bd32ef2a4f650abc067fa
- affected>= aa7253c2393f6dcd6a1468b0792f6da76edad917 and < 77bb0bbfcc4e777ca653174689e5e363f8ee63d1
- affected>= aa7253c2393f6dcd6a1468b0792f6da76edad917 and < 1c89da3baa2b1f269178afa87dc30479b8535776
- affected>= aa7253c2393f6dcd6a1468b0792f6da76edad917 and < 0c054227479ed7e36ebccb3a558bc0ef698264f6
- affected8a8315a5960bd2b5ffc75f44fc089e57c3b17c44
- affectedff20f1875889dbe4a67c9298e609d7c88cf6456d
- affected>= 5.15.61 and < 5.15.212
- affected>= 5.18.18 and < 5.19
- affected>= 5.19.2 and < 5.20
- affected6.0
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.