CVE-2026-68130

Source
https://cve.org/CVERecord?id=CVE-2026-68130
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-68130.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-68130
Downstream
Published
2026-08-10T11:58:52.653Z
Modified
2026-08-21T03:30:18.558534499Z
Summary
ksmbd: defer destroy_previous_session() until after NTLM authentication
Details

In the Linux kernel, the following vulnerability has been resolved:

ksmbd: defer destroyprevioussession() until after NTLM authentication

In ntlmauthenticate(), destroyprevioussession() is called using a user pointer resolved from the client-supplied NTLM blob username field before the NTLMv2 response is validated. An authenticated attacker can set the NTLM blob username to match a victim account and set PreviousSessionId to the victim's session ID; destroyprevioussession() destroys the victim's session while ksmbddecodentlmsspauth_blob() subsequently rejects the request with -EPERM.

Move destroyprevioussession() and the previd assignment to after ksmbddecodentlmsspauthblob() returns success and use sess->user rather than the pre-authentication lookup result. This matches the ordering already used by krb5authenticate(), where destroyprevioussession() is called only after ksmbdkrb5authenticate() returns success.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/68xxx/CVE-2026-68130.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9
Fixed
370b0ec8822b69c9073265e16b7daaa8201c9a4f
Fixed
5c833074b549e5db125436a6f681af682261f785
Fixed
243f1614ef2aca2d62a744575f1c24b07cd42757
Fixed
18705cace0619fd2123737dcd028147774f38181
Fixed
0ff12308c8a6c16ab68f0a487ffa93d69001dc18
Fixed
c74801ee524f477c174a1899782b6c3b6918d407

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-68130.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.15.0
Fixed
6.1.183
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.148
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.101
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.42
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.6

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-68130.json"