Impact
The vulnerability resides in the Linux kernel's ksmbd SMB2 lock handling. When a mid‑batch SMB2_LOCK request grants locks, the granted lock structures are published immediately to connection- and file-wide lock lists while still tracked on an interim rollback list. If a later element in the same lock array fails, the routine attempts to roll back previously granted locks by walking the rollback list. However, because the published lock object may already be freed by a concurrent UNLOCK request, the rollback operation can operate on a freed object, causing a use‑after‑free followed by a double‑free of the ksmbd_lock and struct file_lock instances. This manifests as a classic use‑after‑free weakness (CWE‑416) that can corrupt memory or allow an attacker to execute arbitrary code on the vulnerable host.
Affected Systems
All current Linux kernel implementations incorporating the ksmbd SMB2 daemon before the inclusion of the fix are affected. No specific version identifiers are supplied, so any system running older kernel releases without the patch is vulnerable until the fix is applied.
Risk and Exploitability
The CVSS score of 8.8 classifies this as a high‑severity vulnerability, but the EPSS score of less than 1% indicates a very low probability of exploitation at present. The vulnerability is not listed in CISA’s KEV catalog. An attacker would need to send crafted SMB2_LOCK requests from a remote client that can interact with the vulnerable kernel, making the attack vector network‑based. Successful exploitation could lead to memory corruption, kernel crashes, or privilege escalation, allowing the attacker to gain full control of the affected host.
OpenCVE Enrichment