Description
In the Linux kernel, the following vulnerability has been resolved:

ksmbd: defer publishing granted locks to prevent UAF/double-free race

In smb2_lock(), mid-batch granted locks are published to connection-wide
(conn->lock_list) and file-wide (fp->lock_list) lists immediately upon
vfs_lock_file() success, while also remaining tracked on the stack-local
rollback_list.

If a subsequent element in the same SMB2_LOCK request array fails
validation or execution, the thread jumps to out: and walks
rollback_list to undo previously granted locks. However, because the
granted lock was already published to conn->lock_list, a concurrent
UNLOCK request on the same connection can find the lock object and
kfree() it before the rollback loop executes.

When the granting thread subsequently walks rollback_list, it
dereferences and frees the already-freed ksmbd_lock structure, resulting
in a Use-After-Free and Double-Free (on both ksmbd_lock and struct
file_lock).

Fix this by deferring the publication of granted locks to
conn->lock_list and fp->lock_list until after the entire array of lock
elements has been processed without error. Mid-batch grants remain
tracked exclusively on the request-local rollback_list until the whole
batch succeeds, eliminating the race window.
Published: 2026-09-17
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Use-After-Free and Double-Free leading to potential arbitrary code execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability resides in the Linux kernel's ksmbd SMB2 lock handling. When a mid‑batch SMB2_LOCK request grants locks, the granted lock structures are published immediately to connection- and file-wide lock lists while still tracked on an interim rollback list. If a later element in the same lock array fails, the routine attempts to roll back previously granted locks by walking the rollback list. However, because the published lock object may already be freed by a concurrent UNLOCK request, the rollback operation can operate on a freed object, causing a use‑after‑free followed by a double‑free of the ksmbd_lock and struct file_lock instances. This manifests as a classic use‑after‑free weakness (CWE‑416) that can corrupt memory or allow an attacker to execute arbitrary code on the vulnerable host.

Affected Systems

All current Linux kernel implementations incorporating the ksmbd SMB2 daemon before the inclusion of the fix are affected. No specific version identifiers are supplied, so any system running older kernel releases without the patch is vulnerable until the fix is applied.

Risk and Exploitability

The CVSS score of 8.8 classifies this as a high‑severity vulnerability, but the EPSS score of less than 1% indicates a very low probability of exploitation at present. The vulnerability is not listed in CISA’s KEV catalog. An attacker would need to send crafted SMB2_LOCK requests from a remote client that can interact with the vulnerable kernel, making the attack vector network‑based. Successful exploitation could lead to memory corruption, kernel crashes, or privilege escalation, allowing the attacker to gain full control of the affected host.

Generated by OpenCVE AI on September 20, 2026 at 01:52 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the kernel patch that defers publication of granted locks until the entire SMB2_LOCK array is successfully processed.
  • If a timely kernel update is unavailable, temporarily disable the ksmbd SMB2 daemon to prevent exploitation.
  • Restrict SMB traffic to trusted networks and enforce strong authentication to reduce the attack surface.

Generated by OpenCVE AI on September 20, 2026 at 01:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 02:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: ksmbd: defer publishing granted locks to prevent UAF/double-free race In smb2_lock(), mid-batch granted locks are published to connection-wide (conn->lock_list) and file-wide (fp->lock_list) lists immediately upon vfs_lock_file() success, while also remaining tracked on the stack-local rollback_list. If a subsequent element in the same SMB2_LOCK request array fails validation or execution, the thread jumps to out: and walks rollback_list to undo previously granted locks. However, because the granted lock was already published to conn->lock_list, a concurrent UNLOCK request on the same connection can find the lock object and kfree() it before the rollback loop executes. When the granting thread subsequently walks rollback_list, it dereferences and frees the already-freed ksmbd_lock structure, resulting in a Use-After-Free and Double-Free (on both ksmbd_lock and struct file_lock). Fix this by deferring the publication of granted locks to conn->lock_list and fp->lock_list until after the entire array of lock elements has been processed without error. Mid-batch grants remain tracked exclusively on the request-local rollback_list until the whole batch succeeds, eliminating the race window.
Title ksmbd: defer publishing granted locks to prevent UAF/double-free race
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:53:30.727Z

Reserved: 2026-09-11T19:38:34.790Z

Link: CVE-2026-90162

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:09.517

Modified: 2026-09-18T18:17:44.827

Link: CVE-2026-90162

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T02:00:13Z

Weaknesses