Impact
The defect occurs inside the Linux kernel’s ksmbd module when it frees a file_lock that is still attached to the VFS blocked-request graph. The freed lock remains reachable via linked lists, and the code later asserts that the list must be empty, triggering a BUG_ON and a kernel panic. This results in system-wide unavailability because the kernel crashes, requiring a reboot. The weakness represents an improper resource release that can lead to a use‑after‑free situation.
Affected Systems
The vulnerability affects the Linux kernel’s ksmbd service. No specific kernel version is listed, so any kernel that includes the vulnerable ksmbd implementation and has not been patched is potentially impacted.
Risk and Exploitability
The EPSS score is below 1% and the issue is not listed in the CISA KEV catalog, suggesting a low probability of exploitation. However, a malicious actor who can send crafted SMB requests to the ksmbd daemon could trigger the faulty lock handling and cause the crash, leading to a denial‑of‑service. The lack of a CVSS score precludes a quantified severity assessment, but the high impact on availability warrants prompt remediation.
OpenCVE Enrichment