CVE-2026-80926
Gravedad CVSS v3.1:
CRÍTICA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
11/09/2026
Última modificación:
03/10/2026
Descripción
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
ksmbd: fix use-after-free in oplock break notification<br />
<br />
smb2_oplock_break_noti() reads opinfo->conn without any lock and<br />
dereferences it after two allocations which may sleep. When the<br />
durable handle owning the oplock is disconnected, session_fd_check()<br />
clears opinfo->conn and drops its conn reference under ci->m_lock, and<br />
the last ksmbd_conn_put() frees the connection. A break triggered by<br />
another connection that races with the teardown can then resurrect the<br />
freed connection: ksmbd_conn_get() is a plain atomic_inc, and the<br />
queued break work later dereferences the stale conn via<br />
ksmbd_conn_write(), a use-after-free reachable by any authenticated<br />
client holding a durable batch oplock.<br />
<br />
Thread the caller&#39;s inode into the notification path instead of taking<br />
a new reference on it. Every caller of oplock_break() already holds a<br />
live ksmbd_file (or an explicit ksmbd_inode_lookup_lock() reference,<br />
in the parent lease break paths) on the inode that owns the break<br />
target&#39;s oplock list, so ci cannot be freed during the call, and its<br />
lock can be taken without dereferencing opinfo->o_fp, which a<br />
concurrent close may free. Select and pin the connection under<br />
ci->m_lock, the same lock session_fd_check() and<br />
ksmbd_reopen_durable_fd() use to update opinfo->conn, so a concurrent<br />
detach either loses the race to the clear or keeps the connection<br />
alive until the notification work releases it. Transfer the reference<br />
to the work item and release it on allocation failures.
Impacto
Puntuación base 3.x
9.80
Gravedad 3.x
CRÍTICA
Referencias a soluciones, herramientas e información
- https://git.kernel.org/stable/c/0e753899627b5e28a9fea8bca98262a6f65a2452
- https://git.kernel.org/stable/c/5de0527f782430b1109a447646e32033ad018a6a
- https://git.kernel.org/stable/c/892f643b141aee3f7aa7c0fc61ddcb55c59f1996
- https://git.kernel.org/stable/c/8cc98db4fc590e6c7d9db6529320982ee16c5d1d
- https://git.kernel.org/stable/c/c8279ae8df68cce9cd3b785e85f7a86c80a46e78


