Executive brief
A vulnerability exists in the Linux kernel's ksmbd component, which provides SMB file sharing services. An attacker could exploit this flaw to cause a system crash or potentially execute unauthorized code by triggering a memory error during file handle cleanup. This could lead to a complete loss of service availability or unauthorized access to data stored on the affected server.
Technical details
A use-after-free (UAF) vulnerability exists in the ksmbd module of the Linux kernel within the __ksmbd_close_fd() function. The issue is caused by asymmetric cleanup of byte-range locks when a durable file handle survives a session disconnect (TCP close without SMB2_LOGOFF). While the file pointer's connection reference (fp->conn) is set to NULL to preserve the handle, the associated lock entries remain on the connection's lock list. When the durable scavenger thread later attempts to clean up these locks, it performs a spin_lock on a NULL or already freed connection object. This can be triggered remotely without authentication, leading to a kernel slab use-after-free. Patches have been released for various stable kernel branches including 6.6.y, 6.12.y, 6.18.y, and 7.0.y.
Affected products
- Linux Linux Kernel 6.6.32 to 6.7, 6.9 to 6.12.84, 6.13 to 6.18.25, 6.19 to 7.0.2
Timeline
- 2026-05-01: advisory: Initial NVD publication
- 2026-05-17: patched: Final stable tree patches applied
References
- https://git.kernel.org/stable/c/0000a7780e0e446a28a273572f6ea8f7f582f694
- https://git.kernel.org/stable/c/235e32320a470fcd3998fb3774f2290a0eb302a1
- https://git.kernel.org/stable/c/3d6682726c2d3a46d31dae88b8166786b09b03ad
- https://git.kernel.org/stable/c/b34fc42cfe922e551f7a27d3ac3bb016e41d7dd9
- https://git.kernel.org/stable/c/e33c65f011980b4ad4abfd93585ec2079856368f