9.8

CVE-2026-43379

ksmbd: fix use-after-free in smb_lazy_parent_lease_break_close()

In the Linux kernel, the following vulnerability has been resolved:

ksmbd: fix use-after-free in smb_lazy_parent_lease_break_close()

opinfo pointer obtained via rcu_dereference(fp->f_opinfo) is being
accessed after rcu_read_unlock() has been called. This creates a
race condition where the memory could be freed by a concurrent
writer between the unlock and the subsequent pointer dereferences
(opinfo->is_lease, etc.), leading to a use-after-free.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
Produkt Linux
Default Statusunaffected
Version 27b40b7bfcd121fe13a150ffe11957630cf49246
Version < bf4d66d72e4a9e268c1012c331ce9eaedb5e2086
Status affected
Version 5fb282ba4fef8985a5acf2b32681f2ec07732561
Version < 960699317d39f46611f4ebeb69edc567c1f4e6b6
Status affected
Version 5fb282ba4fef8985a5acf2b32681f2ec07732561
Version < dbbd328cf58261ca239756fe1c0d10c9518d3399
Status affected
Version 5fb282ba4fef8985a5acf2b32681f2ec07732561
Version < b3568347c51c46e2cabc356bc34676df98296619
Status affected
Version 5fb282ba4fef8985a5acf2b32681f2ec07732561
Version < eac3361e3d5dd8067b3258c69615888eb45e9f25
Status affected
HerstellerLinux
Produkt Linux
Default Statusaffected
Version 6.9
Status affected
Version 0
Version < 6.9
Status unaffected
Version <= 6.6.*
Version 6.6.130
Status unaffected
Version <= 6.12.*
Version 6.12.78
Status unaffected
Version <= 6.18.*
Version 6.18.19
Status unaffected
Version <= 6.19.*
Version 6.19.9
Status unaffected
Version <= *
Version 7.0
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.06% 0.189
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.