Description
In the Linux kernel, the following vulnerability has been resolved:

ksmbd: fix use-after-free in oplock break notification

smb2_oplock_break_noti() reads opinfo->conn without any lock and
dereferences it after two allocations which may sleep. When the
durable handle owning the oplock is disconnected, session_fd_check()
clears opinfo->conn and drops its conn reference under ci->m_lock, and
the last ksmbd_conn_put() frees the connection. A break triggered by
another connection that races with the teardown can then resurrect the
freed connection: ksmbd_conn_get() is a plain atomic_inc, and the
queued break work later dereferences the stale conn via
ksmbd_conn_write(), a use-after-free reachable by any authenticated
client holding a durable batch oplock.

Thread the caller's inode into the notification path instead of taking
a new reference on it. Every caller of oplock_break() already holds a
live ksmbd_file (or an explicit ksmbd_inode_lookup_lock() reference,
in the parent lease break paths) on the inode that owns the break
target's oplock list, so ci cannot be freed during the call, and its
lock can be taken without dereferencing opinfo->o_fp, which a
concurrent close may free. Select and pin the connection under
ci->m_lock, the same lock session_fd_check() and
ksmbd_reopen_durable_fd() use to update opinfo->conn, so a concurrent
detach either loses the race to the clear or keeps the connection
alive until the notification work releases it. Transfer the reference
to the work item and release it on allocation failures.
Published: 2026-09-11
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

A use‑after‑free flaw exists in the Linux kernel’s ksmbd SMB server. The flaw occurs when an oplock break notification reads a connection pointer without taking the necessary lock and dereferences it after multiple allocations that may sleep. If a durable batch oplock is disconnected, the connection can be freed while a queued break task is still pending, allowing the task to dereference a stale pointer. An authenticated SMB client that holds such an oplock can trigger this race, potentially achieving arbitrary kernel code execution.

Affected Systems

The defect lies in the ksmbd component of the Linux kernel. Any distribution that ships a kernel image with the SMB server enabled is affected; the dedicated patch applies to all kernel versions prior to the fix. No explicit affected‑version range is provided, so all unsupported kernels that contain ksmbd are vulnerable.

Risk and Exploitability

The CVSS score of 9.8 reflects a critical severity flaw that can grant kernel‑level control. The EPSS score of less than 1% indicates a low probability of exploitation at the time of assessment, and the vulnerability is not yet recorded in CISA’s KEV list. The likely attack vector involves an authenticated SMB session that holds a durable batch oplock, which enables the race condition that leads to the use‑after‑free.

Generated by OpenCVE AI on September 21, 2026 at 03:17 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a kernel update that includes the ksmbd oplock‑break fix
  • If an update is not immediately available, disable the SMB server or block durable batch oplocks to eliminate the race condition
  • Reboot the system after updating the kernel to load the corrected code

Generated by OpenCVE AI on September 21, 2026 at 03:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 21 Sep 2026 13:30:00 +0000


Mon, 21 Sep 2026 03:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in oplock break notification smb2_oplock_break_noti() reads opinfo->conn without any lock and dereferences it after two allocations which may sleep. When the durable handle owning the oplock is disconnected, session_fd_check() clears opinfo->conn and drops its conn reference under ci->m_lock, and the last ksmbd_conn_put() frees the connection. A break triggered by another connection that races with the teardown can then resurrect the freed connection: ksmbd_conn_get() is a plain atomic_inc, and the queued break work later dereferences the stale conn via ksmbd_conn_write(), a use-after-free reachable by any authenticated client holding a durable batch oplock. Thread the caller's inode into the notification path instead of taking a new reference on it. Every caller of oplock_break() already holds a live ksmbd_file (or an explicit ksmbd_inode_lookup_lock() reference, in the parent lease break paths) on the inode that owns the break target's oplock list, so ci cannot be freed during the call, and its lock can be taken without dereferencing opinfo->o_fp, which a concurrent close may free. Select and pin the connection under ci->m_lock, the same lock session_fd_check() and ksmbd_reopen_durable_fd() use to update opinfo->conn, so a concurrent detach either loses the race to the clear or keeps the connection alive until the notification work releases it. Transfer the reference to the work item and release it on allocation failures.
Title ksmbd: fix use-after-free in oplock break notification
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-21T13:14:19.421Z

Reserved: 2026-08-26T14:34:25.802Z

Link: CVE-2026-80926

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:18:56.257

Modified: 2026-09-21T14:17:21.413

Link: CVE-2026-80926

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T03:30:08Z

Weaknesses