Executive brief
A vulnerability was identified in the Linux kernel's ksmbd component, which provides SMB file sharing services. When using SMB3 multichannel features, the system could incorrectly manage file locks across different network connections. This could lead to a system crash or memory corruption, potentially impacting the availability of the file server.
Technical details
A use-after-free vulnerability exists in the ksmbd module of the Linux kernel due to improper synchronization of byte-range locks. In SMB3 multichannel scenarios, the connection handling a LOCK request may differ from the connection that opened the file. The kernel was removing connection list entries using a spinlock (llist_lock) associated with the file-opening connection rather than the lock-owning connection. This mismatch allows concurrent traversals to access freed 'ksmbd_lock' and 'file_lock' objects. The fix involves explicitly tracking and referencing the connection that owns each lock to ensure the correct lock is held during unlock, rollback, and close operations.
Affected products
- Linux Linux kernel f5a544e3bab7 to 22d38cf75b55, 427faaa52b0b, 5fecc15a30cb, 66eb3643164e, c1016dd1d8b2, ea5c9bf99f62, fe20d492a69a
Timeline
- 2026-07-25: disclosed: Initial advisory publication
References
- https://git.kernel.org/stable/c/22d38cf75b556c20b039743bdf3654d535b858be
- https://git.kernel.org/stable/c/427faaa52b0b399940c1a88065a5c310d10dad15
- https://git.kernel.org/stable/c/5fecc15a30cb9ebd310f7b52c1ab607edcea78f6
- https://git.kernel.org/stable/c/66eb3643164e5e1029907793926c132f8b5c6148
- https://git.kernel.org/stable/c/c1016dd1d8b2bcd1158bbaabe94a31bb7e7431fb
- https://git.kernel.org/stable/c/ea5c9bf99f626a15cc59f645dc895f2b3f01992e
- https://git.kernel.org/stable/c/fe20d492a69a6f79e637f438072b212e21ed3b78