Kernel-level SMB server bug in the Linux kernel allows authenticated clients to corrupt/free kernel memory — widespread impact on Linux hosts and potential kernel RCE makes this high-profile.
CVE-2026-80926
ksmbd use-after-free in Linux kernel allows kernel compromise via SMB oplock break
Is CVE-2026-80926 being exploited?
Not confirmed. CVE-2026-80926 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.43% probability of exploitation in the next 30 days.
How severe is CVE-2026-80926?
CVE-2026-80926 is rated Critical with a CVSS score of 9.8. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-80926?
Yes. A fix has been recorded for CVE-2026-80926. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-80926 affect?
CVE-2026-80926 affects Linux kernel (ksmbd in-kernel SMB server), Linux distributions with ksmbd enabled. Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-80926?
Apply kernel security updates or disable ksmbd/limit SMB access immediately
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Authenticated SMB client can trigger a use-after-free in ksmbd, enabling kernel memory corruption leading to crash or possible kernel RCE/privilege escalation.
Immediate action required
- affected>= e735dbd489e3ea02be78dba991056fe1138be51e and < c8279ae8df68cce9cd3b785e85f7a86c80a46e78
- affected>= b003086d76968298f22e7cf62239833b5a3a06b1 and < 8cc98db4fc590e6c7d9db6529320982ee16c5d1d
- affected>= b003086d76968298f22e7cf62239833b5a3a06b1 and < 0e753899627b5e28a9fea8bca98262a6f65a2452
- affected945a86b21b40fb17183f5b27461baa6f03e2467f
- affected1ff58dcfcab434ebb51649da33774fbb8e1f7b67
- affected75e33deda658c1ab3a9336cbdb1436536f9b3660
- affected>= 6.18.36 and < 6.18.51
- affected>= 6.6.143 and < 6.7
- affected>= 6.12.94 and < 6.13
- affected>= 7.0.13 and < 7.1
- affected7.1
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.