Executive brief
A vulnerability in the Linux kernel's SMB server component (ksmbd) can cause a system deadlock. This occurs when a user attempts to create a file link using the 'ReplaceIfExists' flag on an existing file. An exploit could lead to a denial-of-service condition, causing the affected system to become unresponsive and disrupting file-sharing operations.
Technical details
The vulnerability is a deadlock (CWE-667) within the ksmbd_vfs_kern_path_locked() and ksmbd_vfs_link() functions in the Linux kernel's SMB server. When smb2_create_link() is invoked with the ReplaceIfExists flag and the target name exists, ksmbd_vfs_kern_path_locked() successfully locks the parent directory. If the file is subsequently removed via ksmbd_vfs_remove_file(), a subsequent call to ksmbd_vfs_link() attempts to acquire the same parent directory lock while it is still held, resulting in a deadlock. The fix involves moving the ksmbd_vfs_kern_path_unlock() call to occur before ksmbd_vfs_link() is executed.
Affected products
- Linux Linux Kernel 5.15 to 5.15.190, 5.16 to 6.1.149, 6.2 to 6.6.103, 6.7 to 6.12.43, 6.13 to 6.15.11, 6.16 to 6.16.2
Timeline
- 2025-09-04: disclosed
- 2025-09-04: advisory
- 2025-08-28: patched: Patch committed to stable tree
References
- https://git.kernel.org/stable/c/1e858a7a51c7b8b009d8f246de7ceb7743b44a71
- https://git.kernel.org/stable/c/814cfdb6358d9b84fcbec9918c8f938cc096a43a
- https://git.kernel.org/stable/c/9d5012ffe14120f978ee34aef4df3d6cb026b7c4
- https://git.kernel.org/stable/c/a726fef6d7d4cfc365d3434e3916dbfe78991a33
- https://git.kernel.org/stable/c/a7dddd62578c2eb6cb28b8835556a121b5157323
- https://git.kernel.org/stable/c/ac98d54630d5b52e3f684d872f0d82c06c418ea9
- https://git.kernel.org/stable/c/d5fc1400a34b4ea5e8f2ce296ea12bf8c8421694