HOMEVULNERABILITIESCVE-2026-23220
NONE

CVE-2026-23220

Published: February 18, 2026· Updated: Feb 23, 2026

EPSS:0.02%probability of exploitation in 30 daysPercentile:4.2th

Official Description

In the Linux kernel, the following vulnerability has been resolved:

ksmbd: fix infinite loop caused by next_smb2_rcv_hdr_off reset in error paths

The problem occurs when a signed request fails smb2 signature verification

check. In __process_request(), if check_sign_req() returns an error,

set_smb2_rsp_status(work, STATUS_ACCESS_DENIED) is called.

set_smb2_rsp_status() set work->next_smb2_rcv_hdr_off as zero. By resetting

next_smb2_rcv_hdr_off to zero, the pointer to the next command in the chain

is lost. Consequently, is_chained_smb2_message() continues to point to

the same request header instead of advancing. If the header's NextCommand

field is non-zero, the function returns true, causing __handle_ksmbd_work()

to repeatedly process the same failed request in an infinite loop.

This results in the kernel log being flooded with "bad smb2 signature"

messages and high CPU usage.

This patch fixes the issue by changing the return value from

SERVER_HANDLER_CONTINUE to SERVER_HANDLER_ABORT. This ensures that

the processing loop terminates immediately rather than attempting to

continue from an invalidated offset.

NVD Source

Technical Analysis

CVE-2026-23220 requires local access, meaning attackers must already have a foothold on the target system.

Exploitation requires some privileges, which limits the exposure to scenarios where an attacker has already gained initial access.

Affected Vendors & Products

Mentioned vendors (from description):
Linux
CPE data not yet available in NVD for this CVE.

Exploit & PoC Resources

NO KNOWN EXPLOITNo public exploit confirmed at this time
External links open in a new tab. Always verify in a controlled environment before use.

All References (6)

Quick Facts

CVE IDCVE-2026-23220
SeverityNONE
CISA KEVNo
EPSS (30d)0.02%
PublishedFeb 18, 2026

Recommended Actions

  • Apply vendor patches immediately
  • Monitor CVE-2026-23220 in threat intel feeds
  • Review IDS/IPS signatures for exploitation attempts
Data sourced from NVD (NIST), CISA KEV, and EPSS (FIRST). Analysis generated by CTIWATCH.COM. CVE data is provided under the NVD usage policy.