CVE-2026-64390
Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
25/07/2026
Última modificación:
25/07/2026
Descripción
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
ksmbd: track the connection owning a byte-range lock<br />
<br />
SMB2_LOCK adds each granted byte-range lock to both the file lock list<br />
and the lock list of the connection which handled the request. The<br />
final close and durable handle paths, however, remove the connection<br />
list entry while holding fp->conn->llist_lock.<br />
<br />
With SMB3 multichannel, the connection handling the LOCK request can be<br />
different from the connection which opened the file. The entry can<br />
therefore be removed under a different spinlock from the one protecting<br />
the list it belongs to. A concurrent traversal can then access freed<br />
struct ksmbd_lock and struct file_lock objects.<br />
<br />
Record the connection owning each lock&#39;s clist entry and hold a<br />
reference to it while the entry is linked. Use that connection and its<br />
llist_lock for unlock, rollback, close, and durable preserve. Durable<br />
reconnect assigns the new connection as the owner when publishing the<br />
locks again.
Impacto
Referencias a soluciones, herramientas e información
- https://git.kernel.org/stable/c/22d38cf75b556c20b039743bdf3654d535b858be
- https://git.kernel.org/stable/c/427faaa52b0b399940c1a88065a5c310d10dad15
- https://git.kernel.org/stable/c/5fecc15a30cb9ebd310f7b52c1ab607edcea78f6
- https://git.kernel.org/stable/c/66eb3643164e5e1029907793926c132f8b5c6148
- https://git.kernel.org/stable/c/c1016dd1d8b2bcd1158bbaabe94a31bb7e7431fb
- https://git.kernel.org/stable/c/ea5c9bf99f626a15cc59f645dc895f2b3f01992e
- https://git.kernel.org/stable/c/fe20d492a69a6f79e637f438072b212e21ed3b78



