Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-74522

Gravedad CVSS v3.1:
ALTA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
15/08/2026
Última modificación:
19/08/2026

Descripción

*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> ksmbd: fix use-after-free in __close_file_table_ids()<br /> <br /> A ksmbd_file can remain alive after logical close while another session<br /> holds a temporary reference obtained through ksmbd_lookup_fd_inode().<br /> ksmbd_close_fd() currently marks the file closed and drops the idr-owned<br /> reference, but leaves the pointer published in the closing session&amp;#39;s idr<br /> until the final reference is dropped.<br /> <br /> If the foreign holder performs the final ksmbd_fd_put(), __put_fd_final()<br /> supplies the foreign session&amp;#39;s file table to __ksmbd_close_fd(). The object<br /> is then freed without being removed from its owner&amp;#39;s idr, and the owner<br /> session later dereferences the stale pointer during file-table teardown.<br /> <br /> Remove the volatile id from the owner&amp;#39;s idr while ksmbd_close_fd() still<br /> holds that table&amp;#39;s lock, and clear volatile_id before dropping<br /> the idr-owned reference. A later foreign final put then only performs<br /> physical destruction and cannot remove the object from the wrong table.