CVE-2026-53046 Details
Description
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free from async crypto on Qualcomm crypto engine ksmbd_crypt_message() sets a NULL completion callback on AEAD requests and does not handle the -EINPROGRESS return code from async hardware crypto engines like the Qualcomm Crypto Engine (QCE). When QCE returns -EINPROGRESS, ksmbd treats it as an error and immediately frees the request while the hardware DMA operation is still in flight. The DMA completion callback then dereferences freed memory, causing a NULL pointer crash: pc : qce_skcipher_done+0x24/0x174 lr : vchan_complete+0x230/0x27c ... el1h_64_irq+0x68/0x6c ksmbd_free_work_struct+0x20/0x118 [ksmbd] ksmbd_exit_file_cache+0x694/0xa4c [ksmbd] Use the standard crypto_wait_req() pattern with crypto_req_done() as the completion callback, matching the approach used by the SMB client in fs/smb/client/smb2ops.c. This properly handles both synchronous engines (immediate return) and async engines (-EINPROGRESS followed by callback notification).
A use-after-free vulnerability has been identified in the Linux kernel's ksmbd component. This issue arises in versions of the kernel that utilize the Qualcomm Crypto Engine (QCE) for asynchronous cryptographic operations. The vulnerability occurs because ksmbd_crypt_message() does not properly manage the completion callback for Authenticated Encryption with Associated Data (AEAD) requests. When QCE returns a -EINPROGRESS status, indicating that a Direct Memory Access (DMA) operation is still ongoing, ksmbd incorrectly interprets this as an error and prematurely frees the request. This mismanagement allows the DMA completion callback to access freed memory, leading to a NULL pointer dereference and a crash. The vulnerability has been addressed by modifying the callback handling to use the standard crypto_wait_req() pattern, ensuring that both synchronous and asynchronous operations are correctly managed.
Users should update to the latest version of the Linux kernel where this vulnerability has been fixed. The specific commit that addresses this issue is 3e298897f41c61450c2e7a4f457e8b2485eb35b3.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/3e298897f41c61450c2e7a4f457e8b2485eb35b3 | kernel.org | Patch |
| https://git.kernel.org/stable/c/57b47231055b431ed0a1a55f33cac32981564405 | kernel.org | Patch |
| https://git.kernel.org/stable/c/7164b3953cefd540e7ebca828c793bc6869cfbc4 | kernel.org | Patch |
| https://git.kernel.org/stable/c/8ef183216feaa24b66b940510d8b68f680eb56e9 | kernel.org | Patch |
| https://git.kernel.org/stable/c/8fcefe840fa8c14ce667768e5b043286ac3bbcbe | kernel.org | Patch |
| https://git.kernel.org/stable/c/b46aa129fa2807bfe1545fe74d9295d53c51520b | kernel.org | Patch |
| https://git.kernel.org/stable/c/cc2da381875d4a67026e4c8feb3dba51a2a2d1bc | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-416 | Use After Free | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 5.15, < 5.15.209 >= 5.16, < 6.1.175 >= 6.2, < 6.6.141 >= 6.7, < 6.12.91 >= 6.13, < 6.18.33 >= 6.19, < 7.0.10 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 21, 2026 | Initial Analysis | [email protected] |
| Jun 28, 2026 | CVE Modified | kernel.org |
| Jun 24, 2026 | New CVE Received | kernel.org |