Impact
The kernel function smbdirect_socket_destroy() releases child sockets while holding the listener’s handler lock, freeing the child socket’s CM ID before the listener’s CM ID is destroyed. This ordering allows _cma_cancel_listens() to access a freed child ID, resulting in a KASAN use‑after‑free. The fault can lead to a kernel panic or memory corruption that an attacker might exploit to gain elevated privileges.
Affected Systems
The flaw exists in the Linux kernel’s SMB Direct implementation, affecting all currently released and upcoming kernels that include the smbdirect code path. Vendor/product information lists only the Linux kernel, and no specific version list is supplied, so any kernel running ksmbd without the recent fix is potentially vulnerable.
Risk and Exploitability
The CVSS score is not disclosed, but the EPSS score of less than 1% indicates a very low current exploitation rate, and the vulnerability is not listed in the CISA KEV catalog. Attackers would need to trigger the listener shutdown or otherwise cause ksmbd to release sockets while the handler lock is held. The real consequence is a use‑after‑free that could allow local privilege escalation or denial of service if exploited.
OpenCVE Enrichment