Junglewise Threat Intelligence

CVE-2026-64142: Linux Kernel ksmbd Use-After-Free in Durable Scavenger

CVE-2026-64142 · Severity: info · CVSS 7.5 · Published 2026-07-19

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's ksmbd component, which provides SMB file sharing services. The flaw involves a race condition in how the system cleans up expired file handles, potentially leading to memory corruption or a system crash. In a worst-case scenario, this could impact the stability of the file server and the integrity of active data sessions.

Technical details

The vulnerability exists within the ksmbd_durable_scavenger() function due to two primary race conditions. First, the scavenger reuses the 'fp->node' list_head for a local list while it is still linked to 'f_ci->m_fp_list', leading to list corruption. Second, a reference counting race allows the scavenger to free a file pointer (fp) while another thread (such as ksmbd_lookup_fd_inode) still holds a reference, resulting in a use-after-free (UAF). These issues occur during the background expiration of durable SMB2 handles. The fix involves introducing transient references to ensure proper object lifetime management and preventing list head reuse.

Affected products

  • Linux Linux Kernel ksmbd module

Timeline

  • 2026-07-19: advisory: CVE-2026-64142 published
  • 2026-06-01: patched: Fixes committed to stable kernel branches

References

Related threats