CVE-2026-90163

Summary

In the Linux kernel, the following vulnerability has been resolved:

smb/server: call ksmbd_proc_cleanup() on module init failure

When a later initializer fails, the unwind chain releases resources created after procfs and then jumps directly to class_unregister(). Returning an error from module_init() leaves the proc tree and its per-CPU counters allocated.

Affected Software

VendorProductVersion RangeStatus
LinuxLinuxb38f99c1217ae04753340f0fdcd8f35bf56841dc < 7d2cd9269b570347e6e2dd24d4b3c1da868bc91daffected
LinuxLinuxb38f99c1217ae04753340f0fdcd8f35bf56841dc < f43cbe3b58ce989ce420c3bc875d48e7754c8abaaffected
LinuxLinux7.0affected
LinuxLinux0 < 7.0unaffected
LinuxLinux7.2.6 <= 7.2.*unaffected
LinuxLinux7.3-rc1 <= *unaffected

Weaknesses

References