Description
In the Linux kernel, the following vulnerability has been resolved:

ksmbd: serialize oplock close with pending break ownership

close may abort an in-flight oplock break while another breaker already
holds an opinfo reference. Releasing pending_break wakes that waiter, but
without serializing the close transition with bit acquisition it can become
a new break owner through the test_and_set_bit() fast path. It can then
overwrite OPLOCK_CLOSING with OPLOCK_ACK_WAIT and continue a break for
a dying opinfo.

Make OPLOCK_CLOSING terminal once the opinfo is removed from the inode
list. Serialize that transition, pending_break acquisition, and
OPLOCK_ACK_WAIT setup with an opinfo state lock. A breaker which loses
the race releases its ownership and returns -ENOENT. Explicitly wake
pending_break waiters during close so they can observe the terminal state.

Also prevent ACK and timeout paths from replacing OPLOCK_CLOSING with
OPLOCK_STATE_NONE.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Oplock state corruption with potential denial of service
Action: Immediate Patch
AI Analysis

Impact

The vulnerability occurs in the Linux kernel’s ksmbd subsystem, where the close operation for an SMB oplock can race with an ongoing oplock break. This race allows a breaker to overwrite the state bits that normally signal the oplock is closing, potentially causing the kernel to treat a terminal oplock as still active or to continue a break on a removed opinfo. The fault does not directly expose code execution, but it can lead to SMB service instability, data loss, or corruption of shared file state, impacting confidentiality and integrity of files accessed via SMB shares.

Affected Systems

All Linux kernel installations that include the legacy ksmbd implementation and run an SMB service before the patch is applied are affected. The exact kernel version range is unspecified, but any kernel that contains the pre‑patch oplock close logic is vulnerable.

Risk and Exploitability

The EPSS score is reported as less than 1 %, indicating a very low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. No public exploit has been documented. The issue could be triggered by an SMB client that initiates an oplock break while the server processes a close operation, which is feasible in typical SMB workloads. Because the flaw does not involve network‑side input validation or privilege escalation, its attack surface is limited but the impact on SMB reliability is significant.

Generated by OpenCVE AI on September 20, 2026 at 02:46 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a Linux kernel update that includes the ksmbd oplock serialization fix (see commit references in the advisory).
  • If updating the kernel is not immediately possible, disable or block SMB traffic that relies on the ksmbd daemon until a patch is available.
  • After any mitigation, verify that SMB operations no longer trigger oplock state inconsistencies by monitoring logs for oplock related errors or crashes.

Generated by OpenCVE AI on September 20, 2026 at 02:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 03:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: ksmbd: serialize oplock close with pending break ownership close may abort an in-flight oplock break while another breaker already holds an opinfo reference. Releasing pending_break wakes that waiter, but without serializing the close transition with bit acquisition it can become a new break owner through the test_and_set_bit() fast path. It can then overwrite OPLOCK_CLOSING with OPLOCK_ACK_WAIT and continue a break for a dying opinfo. Make OPLOCK_CLOSING terminal once the opinfo is removed from the inode list. Serialize that transition, pending_break acquisition, and OPLOCK_ACK_WAIT setup with an opinfo state lock. A breaker which loses the race releases its ownership and returns -ENOENT. Explicitly wake pending_break waiters during close so they can observe the terminal state. Also prevent ACK and timeout paths from replacing OPLOCK_CLOSING with OPLOCK_STATE_NONE.
Title ksmbd: serialize oplock close with pending break ownership
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:06:56.507Z

Reserved: 2026-09-11T19:38:34.790Z

Link: CVE-2026-90167

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:10.097

Modified: 2026-09-17T17:17:10.097

Link: CVE-2026-90167

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T03:00:11Z

Weaknesses
  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')