9.8
CVE-2026-72381
- EPSS 0.65%
- Veröffentlicht 15.08.2026 05:56:13
- Zuletzt bearbeitet 17.08.2026 06:18:42
- Erkennungen
ksmbd: fix use-after-free of fp->owner.name in durable handle owner check
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: fix use-after-free of fp->owner.name in durable handle owner check
Two concurrent SMB2 durable reconnects (DH2C/DHnC) on the same
persistent_id race the fp->owner.name compare-read in
ksmbd_vfs_compare_durable_owner() against the kfree() in
ksmbd_reopen_durable_fd()'s reopen-success path. fp->owner.name is a
standalone kstrdup() buffer whose lifetime is independent of the fp
refcount, and the two sites share no lock: the compare reads the buffer
while the reopen frees it, so the strcmp() can dereference freed memory.
Commit 7ce4fc40018d ("ksmbd: fix durable reconnect double-bind race in
ksmbd_reopen_durable_fd") made the fp->conn claim atomic under
global_ft.lock (closing the owner.name double-free and the ksmbd_file
write-UAF), but the compare-read versus reopen-free pair was left
unserialized.
BUG: KASAN: slab-use-after-free in strcmp+0x2c/0x80
Read of size 1 by task kworker
strcmp
ksmbd_vfs_compare_durable_owner
smb2_check_durable_oplock
smb2_open
Freed by task kworker:
kfree
ksmbd_reopen_durable_fd
smb2_open
Allocated by task kworker:
kstrdup
session_fd_check
smb2_session_logoff
The buggy address belongs to the cache kmalloc-8
Serialize both sides of the race with fp->f_lock. The global durable
file-table lock still protects the durable reconnect claim, but
fp->owner.name is per-open state and does not need to block unrelated
durable table lookups or reconnects. The teardown is left at its
existing location after the reopen-success point so that an __open_id()
rollback still retains owner.name for a later legitimate reconnect to
verify.Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
712cdf917e77a6444ce3836874829d770db20ee6
Version <
fb978d72052704c6b06c6b0f129fcd60b77169f5
Status
affected
Version
c7f0f0d01c88bdcb8b1694d7d321670013f7ed7d
Version <
93d4d46bf9d442a12ea87278049ec416962c627f
Status
affected
Version
00ce8d6789dae72d042a4522264964c72891ca37
Version <
5a5ac2852cd326529d02f778bc1aa6184701f4d7
Status
affected
Version
49110a8ce654bbe56bef7c5e44cce31f4b102b8a
Version <
ed98719be41389d416953b8ef9f07a07dfea6b2b
Status
affected
Version
49110a8ce654bbe56bef7c5e44cce31f4b102b8a
Version <
38637163501fd9e2f684b8cd275d0db5d79f37c6
Status
affected
Version
c908c853f304a4969b5aa10eba0b50350cc65b80
Status
affected
Version
6.6.142
Version <
6.6.145
Status
affected
Version
6.12.92
Version <
6.12.97
Status
affected
Version
6.18.25
Version <
6.18.40
Status
affected
Version
7.0.2
Version <
7.1
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
7.1
Status
affected
Version
0
Version <
7.1
Status
unaffected
Version <=
6.6.*
Version
6.6.145
Status
unaffected
Version <=
6.12.*
Version
6.12.97
Status
unaffected
Version <=
6.18.*
Version
6.18.40
Status
unaffected
Version <=
7.1.*
Version
7.1.5
Status
unaffected
Version <=
*
Version
7.2
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.65% | 0.483 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
https://git.kernel.org/stable/c/fb978d72052704c6b06c6b0f129fcd60b77169f5
https://git.kernel.org/stable/c/93d4d46bf9d442a12ea87278049ec416962c627f
https://git.kernel.org/stable/c/5a5ac2852cd326529d02f778bc1aa6184701f4d7
https://git.kernel.org/stable/c/ed98719be41389d416953b8ef9f07a07dfea6b2b
https://git.kernel.org/stable/c/38637163501fd9e2f684b8cd275d0db5d79f37c6