Executive brief
A vulnerability exists in the Linux kernel's ksmbd component, which provides SMB file-sharing services. A flaw in how the system manages internal communication handles could allow an attacker to cause system instability or potentially gain unauthorized access to data. This issue stems from a race condition where multiple processes might try to modify the same data simultaneously due to improper locking.
Technical details
A race condition exists in the ksmbd module of the Linux kernel within the management of 'sess->rpc_handle_list'. The vulnerability is caused by improper use of rw_semaphores; specifically, ksmbd_session_rpc_open() incorrectly acquired a read lock instead of a write lock before performing xa_store() and xa_erase() operations on the XArray. Additionally, ksmbd_session_rpc_method() performed xa_load() without any locking. These flaws allow for concurrent modifications and lookups that can result in data corruption or a use-after-free (UAF) if an entry is dereferenced after being removed. The fix involves upgrading to write locks for modifications and ensuring read locks are held during lookups.
Affected products
- Linux Linux Kernel 5.15.145 to 6.17.3; 6.18 and later fixed
Timeline
- 2025-09-30: patched: Initial patch committed to stable tree
- 2025-10-28: disclosed: CVE published
References
- https://git.kernel.org/stable/c/305853cce379407090a73b38c5de5ba748893aee
- https://git.kernel.org/stable/c/5cc679ba0f4505936124cd4179ba66bb0a4bd9f3
- https://git.kernel.org/stable/c/69674b029002b1d90b655f014bdf64f404efa54d
- https://git.kernel.org/stable/c/6b615a8fb3af0baf8126cde3d4fee97d57222ffc
- https://git.kernel.org/stable/c/6bd7e0e55dcea2cf0d391bbc21c2eb069b4be3e1