Description
In the Linux kernel, the following vulnerability has been resolved:

ksmbd: detach blocked lock requests before freeing

A file_lock retained by ksmbd for byte-range lock bookkeeping can still
be part of the VFS blocked-request graph. In particular, the VFS can
chain a new waiter below an already blocked request through
flc_blocked_requests. The ksmbd_file reference count does not cover that
graph.

Both __ksmbd_close_fd() and the cross-request unlock path free these
retained file_lock objects directly. If a dependent waiter is still
attached, locks_release_private() hits
BUG_ON(!list_empty(&flc->flc_blocked_requests)). The same lifetime
mismatch can leave a freed ksmbd_lock reachable through its request-local
llist.

Detach the file_lock from the blocked-request graph before freeing it in
the close, cross-request unlock, and rollback paths. locks_delete_block()
also wakes requests chained below the object. Remove llist when a
completed lock is published so a globally visible ksmbd_lock no longer
points into the submitting worker's stack.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Kernel Panic (Denial of Service)
Action: Immediate Patch
AI Analysis

Impact

The defect occurs inside the Linux kernel’s ksmbd module when it frees a file_lock that is still attached to the VFS blocked-request graph. The freed lock remains reachable via linked lists, and the code later asserts that the list must be empty, triggering a BUG_ON and a kernel panic. This results in system-wide unavailability because the kernel crashes, requiring a reboot. The weakness represents an improper resource release that can lead to a use‑after‑free situation.

Affected Systems

The vulnerability affects the Linux kernel’s ksmbd service. No specific kernel version is listed, so any kernel that includes the vulnerable ksmbd implementation and has not been patched is potentially impacted.

Risk and Exploitability

The EPSS score is below 1% and the issue is not listed in the CISA KEV catalog, suggesting a low probability of exploitation. However, a malicious actor who can send crafted SMB requests to the ksmbd daemon could trigger the faulty lock handling and cause the crash, leading to a denial‑of‑service. The lack of a CVSS score precludes a quantified severity assessment, but the high impact on availability warrants prompt remediation.

Generated by OpenCVE AI on September 20, 2026 at 01:55 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version where the ksmbd patch from commit 215e8816b1ac25176d911abb8704390413ccee4b is applied.
  • If an immediate kernel upgrade is not possible, temporarily disable the ksmbd daemon or the SMB service to prevent the flaw from being exercised.
  • Apply kernel hardening practices such as enabling SELinux or AppArmor with profiles that restrict SMB service privileges to further reduce the attack surface.

Generated by OpenCVE AI on September 20, 2026 at 01:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 02:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: ksmbd: detach blocked lock requests before freeing A file_lock retained by ksmbd for byte-range lock bookkeeping can still be part of the VFS blocked-request graph. In particular, the VFS can chain a new waiter below an already blocked request through flc_blocked_requests. The ksmbd_file reference count does not cover that graph. Both __ksmbd_close_fd() and the cross-request unlock path free these retained file_lock objects directly. If a dependent waiter is still attached, locks_release_private() hits BUG_ON(!list_empty(&flc->flc_blocked_requests)). The same lifetime mismatch can leave a freed ksmbd_lock reachable through its request-local llist. Detach the file_lock from the blocked-request graph before freeing it in the close, cross-request unlock, and rollback paths. locks_delete_block() also wakes requests chained below the object. Remove llist when a completed lock is published so a globally visible ksmbd_lock no longer points into the submitting worker's stack.
Title ksmbd: detach blocked lock requests before freeing
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:06:47.716Z

Reserved: 2026-09-11T19:38:34.790Z

Link: CVE-2026-90155

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:08.607

Modified: 2026-09-17T17:17:08.607

Link: CVE-2026-90155

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T02:00:13Z

Weaknesses