Executive brief
The Linux kernel's SMB file server (ksmbd) contains a memory safety bug that can be triggered when multiple clients attempt to reconnect using durable file handles simultaneously. An attacker with network access to an SMB server can exploit this race condition to read freed memory and potentially achieve remote code execution, disrupting file service availability or compromising system integrity.
Technical details
This is a use-after-free vulnerability in the ksmbd kernel module's durable handle reconnection logic. The race occurs between ksmbd_vfs_compare_durable_owner() (which reads fp->owner.name) and ksmbd_reopen_durable_fd() (which frees it via kfree()). The fp->owner.name buffer is allocated independently via kstrdup() and has no synchronization mechanism protecting concurrent access across these two code paths. An attacker can trigger concurrent SMB2 durable reconnects (DH2C/DHnC) on the same persistent_id to cause the strcmp() call to dereference freed memory, leading to information disclosure or kernel crash. The fix serializes both sides of the race using fp->f_lock to protect the compare-read and free operations. The vulnerability is exploitable remotely over the network without authentication on an exposed SMB server.
Affected products
- Linux Linux kernel affected versions prior to fix (ksmbd module)
Timeline
- 2026-08-15: disclosed: Public disclosure via NVD