Impact
The Linux kernel’s ksmbd module can incorrectly handle deferred locks: when vfs_lock_file() defers a lock, smb2_lock() adds its ksmbd_lock to a rollback list before allocating and registering asynchronous work. If either the allocation or registration fails, the rollback code assumes smb_lock->conn is initialized and dereferences a NULL pointer, causing a kernel panic. Consequently, the SMB service is abruptly terminated. This flaw is a null pointer dereference and use‑after‑free failure, mapped to CWE-476 and CWE-416.
Affected Systems
All Linux kernels that include the ksmbd module before the commit 054bcca4cd9f00719b01f7108b51a2168fb94f15 are potentially impacted. No specific version numbers are listed, so any kernel with ksmbd present could be vulnerable.
Risk and Exploitability
The EPSS score is below 1 % and the vulnerability is not in the CISA KEV catalog, indicating a low probability of widespread exploitation. Based on the description, it is inferred that an attacker who can initiate a lock operation over SMB, such as through a remote SMB connection, could trigger the kernel panic. The flaw leads to service denial without privilege escalation or data exfiltration. Exploitation requires the asynchronous work allocation to fail, which may occur under normal operation or stress, but the overall risk remains low relative to more severe attacks.
OpenCVE Enrichment