Impact
The vulnerability occurs in the Linux kernel’s ksmbd subsystem, where the close operation for an SMB oplock can race with an ongoing oplock break. This race allows a breaker to overwrite the state bits that normally signal the oplock is closing, potentially causing the kernel to treat a terminal oplock as still active or to continue a break on a removed opinfo. The fault does not directly expose code execution, but it can lead to SMB service instability, data loss, or corruption of shared file state, impacting confidentiality and integrity of files accessed via SMB shares.
Affected Systems
All Linux kernel installations that include the legacy ksmbd implementation and run an SMB service before the patch is applied are affected. The exact kernel version range is unspecified, but any kernel that contains the pre‑patch oplock close logic is vulnerable.
Risk and Exploitability
The EPSS score is reported as less than 1 %, indicating a very low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. No public exploit has been documented. The issue could be triggered by an SMB client that initiates an oplock break while the server processes a close operation, which is feasible in typical SMB workloads. Because the flaw does not involve network‑side input validation or privilege escalation, its attack surface is limited but the impact on SMB reliability is significant.
OpenCVE Enrichment