CVE-2026-80926

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
11/09/2026
Last modified:
03/10/2026

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> ksmbd: fix use-after-free in oplock break notification<br /> <br /> smb2_oplock_break_noti() reads opinfo-&gt;conn without any lock and<br /> dereferences it after two allocations which may sleep. When the<br /> durable handle owning the oplock is disconnected, session_fd_check()<br /> clears opinfo-&gt;conn and drops its conn reference under ci-&gt;m_lock, and<br /> the last ksmbd_conn_put() frees the connection. A break triggered by<br /> another connection that races with the teardown can then resurrect the<br /> freed connection: ksmbd_conn_get() is a plain atomic_inc, and the<br /> queued break work later dereferences the stale conn via<br /> ksmbd_conn_write(), a use-after-free reachable by any authenticated<br /> client holding a durable batch oplock.<br /> <br /> Thread the caller&amp;#39;s inode into the notification path instead of taking<br /> a new reference on it. Every caller of oplock_break() already holds a<br /> live ksmbd_file (or an explicit ksmbd_inode_lookup_lock() reference,<br /> in the parent lease break paths) on the inode that owns the break<br /> target&amp;#39;s oplock list, so ci cannot be freed during the call, and its<br /> lock can be taken without dereferencing opinfo-&gt;o_fp, which a<br /> concurrent close may free. Select and pin the connection under<br /> ci-&gt;m_lock, the same lock session_fd_check() and<br /> ksmbd_reopen_durable_fd() use to update opinfo-&gt;conn, so a concurrent<br /> detach either loses the race to the clear or keeps the connection<br /> alive until the notification work releases it. Transfer the reference<br /> to the work item and release it on allocation failures.