Executive brief
A vulnerability exists in the Linux kernel's ksmbd component, which provides SMB file sharing services. An attacker could exploit this flaw to cause a system crash or potentially execute unauthorized code by triggering a memory management error. This could lead to a complete loss of system availability and compromise the confidentiality and integrity of data stored on the affected server.
Technical details
A use-after-free vulnerability exists in the ksmbd (SMB server) implementation within the Linux kernel. The root cause is the immediate freeing of the 'oplock_info' structure using kfree() while it is still being accessed within RCU (Read-Copy-Update) read-side critical sections, such as in opinfo_get() and proc_show_files(). Because there is no RCU grace period delay between nullifying the pointer and freeing the memory, concurrent readers may attempt to perform operations like atomic_inc_not_zero() on already freed memory. This is a network-reachable vulnerability that does not require authentication. The fix involves switching to deferred memory freeing using call_rcu() to ensure all readers have finished before the memory is reclaimed.
Affected products
- Linux Linux Kernel ksmbd component
Timeline
- 2026-03-07: other: Patch authored
- 2026-05-08: advisory: CVE published
References
- https://git.kernel.org/stable/c/08aa9f3c8cf4d0bee44df540dfe34e8d64069f2c
- https://git.kernel.org/stable/c/1d6abf145615dbfe267ce3b0a271f95e3780e18e
- https://git.kernel.org/stable/c/1dfd062caa165ec9d7ee0823087930f3ab8a6294
- https://git.kernel.org/stable/c/302fef75512b2c8329a3f5efab1ae7ba2562387a
- https://git.kernel.org/stable/c/ce8507ee82c888126d8e7565e27c016308d24cde