Impact
A use‑after‑free flaw exists in the Linux kernel’s ksmbd SMB server. The flaw occurs when an oplock break notification reads a connection pointer without taking the necessary lock and dereferences it after multiple allocations that may sleep. If a durable batch oplock is disconnected, the connection can be freed while a queued break task is still pending, allowing the task to dereference a stale pointer. An authenticated SMB client that holds such an oplock can trigger this race, potentially achieving arbitrary kernel code execution.
Affected Systems
The defect lies in the ksmbd component of the Linux kernel. Any distribution that ships a kernel image with the SMB server enabled is affected; the dedicated patch applies to all kernel versions prior to the fix. No explicit affected‑version range is provided, so all unsupported kernels that contain ksmbd are vulnerable.
Risk and Exploitability
The CVSS score of 9.8 reflects a critical severity flaw that can grant kernel‑level control. The EPSS score of less than 1% indicates a low probability of exploitation at the time of assessment, and the vulnerability is not yet recorded in CISA’s KEV list. The likely attack vector involves an authenticated SMB session that holds a durable batch oplock, which enables the race condition that leads to the use‑after‑free.
OpenCVE Enrichment
Debian DSA