Junglewise Threat Intelligence

CVE-2026-64396: Linux Kernel ksmbd use-after-free in SMB2_LOCK cancellation

CVE-2026-64396 · Severity: info · CVSS 0 · Published 2026-07-25

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability exists in the Linux kernel's ksmbd module, which provides SMB file sharing services. An error in how the system handles file lock cancellations can lead to a system crash or memory corruption. This could potentially allow an attacker to disrupt file sharing operations or impact the stability of the server.

Technical details

A use-after-free (UAF) vulnerability exists in the ksmbd component of the Linux kernel due to improper synchronization during SMB2_LOCK deferred-lock cancellation. When a blocking byte-range lock request is deferred, ksmbd registers asynchronous work. If the lock waiter is woken up while the work state is no longer active (e.g., due to concurrent cancellation), the cleanup path may free the 'file_lock' structure while it is still queued in the async_requests list. A concurrent call to smb2_cancel() can then dereference this freed memory. The fix restructures the cleanup logic to ensure the work is dequeued and serialized before the memory is released.

Affected products

  • Linux Linux Kernel 6.1.178, 6.6.145, 6.12.y, 6.13.y, 6.14.y, 6.15.y

Timeline

  • 2026-06-06: other: Patch authored
  • 2026-07-24: patched: Patch committed to stable tree
  • 2026-07-25: advisory: CVE published

References

Related threats