Impact
A flaw in the Linux kernel’s ksmbd component prevents mandatory byte‑range lock checks when the range is a single byte. The check uses inclusive bounds but callers compute the end offset as start plus length minus one, so a one‑byte range is interpreted as empty and the lock check is skipped. This allows concurrent operations to bypass locking controls for reads, writes, copychunk and truncate operations that affect that byte, leading to potential data corruption or loss. The weakness is a race condition (CWE‑362 and CWE‑367).
Affected Systems
Affected systems are all Linux kernel installations that enable the ksmbd SMB server. No specific kernel version numbers are listed in the CVE data; the issue applies broadly to any kernel build that has not yet incorporated the commit that removes the shortcut.
Risk and Exploitability
The CVSS score of 8.1 indicates a high severity rating for this race condition flaw. The EPSS score of less than 1% suggests that, as of this assessment, the likelihood of exploitation is low, and the vulnerability is not currently listed in the CISA KEV catalog. Nonetheless, the flaw can be exploited for data integrity attacks, especially in environments where SMB shares are exposed to untrusted clients. The attack vector is inferred to be local or network‑based SMB access to a Linux host running ksmbd, as the omission occurs during byte‑range handling in file operations over SMB.
OpenCVE Enrichment
Debian DLA
Debian DSA