9.8

CVE-2026-72381

ksmbd: fix use-after-free of fp->owner.name in durable handle owner check

In the Linux kernel, the following vulnerability has been resolved:

ksmbd: fix use-after-free of fp->owner.name in durable handle owner check

Two concurrent SMB2 durable reconnects (DH2C/DHnC) on the same
persistent_id race the fp->owner.name compare-read in
ksmbd_vfs_compare_durable_owner() against the kfree() in
ksmbd_reopen_durable_fd()'s reopen-success path. fp->owner.name is a
standalone kstrdup() buffer whose lifetime is independent of the fp
refcount, and the two sites share no lock: the compare reads the buffer
while the reopen frees it, so the strcmp() can dereference freed memory.

Commit 7ce4fc40018d ("ksmbd: fix durable reconnect double-bind race in
ksmbd_reopen_durable_fd") made the fp->conn claim atomic under
global_ft.lock (closing the owner.name double-free and the ksmbd_file
write-UAF), but the compare-read versus reopen-free pair was left
unserialized.

  BUG: KASAN: slab-use-after-free in strcmp+0x2c/0x80
  Read of size 1 by task kworker
    strcmp
    ksmbd_vfs_compare_durable_owner
    smb2_check_durable_oplock
    smb2_open
  Freed by task kworker:
    kfree
    ksmbd_reopen_durable_fd
    smb2_open
  Allocated by task kworker:
    kstrdup
    session_fd_check
    smb2_session_logoff
  The buggy address belongs to the cache kmalloc-8

Serialize both sides of the race with fp->f_lock.  The global durable
file-table lock still protects the durable reconnect claim, but
fp->owner.name is per-open state and does not need to block unrelated
durable table lookups or reconnects.  The teardown is left at its
existing location after the reopen-success point so that an __open_id()
rollback still retains owner.name for a later legitimate reconnect to
verify.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 712cdf917e77a6444ce3836874829d770db20ee6
Version < fb978d72052704c6b06c6b0f129fcd60b77169f5
Status affected
Version c7f0f0d01c88bdcb8b1694d7d321670013f7ed7d
Version < 93d4d46bf9d442a12ea87278049ec416962c627f
Status affected
Version 00ce8d6789dae72d042a4522264964c72891ca37
Version < 5a5ac2852cd326529d02f778bc1aa6184701f4d7
Status affected
Version 49110a8ce654bbe56bef7c5e44cce31f4b102b8a
Version < ed98719be41389d416953b8ef9f07a07dfea6b2b
Status affected
Version 49110a8ce654bbe56bef7c5e44cce31f4b102b8a
Version < 38637163501fd9e2f684b8cd275d0db5d79f37c6
Status affected
Version c908c853f304a4969b5aa10eba0b50350cc65b80
Status affected
Version 6.6.142
Version < 6.6.145
Status affected
Version 6.12.92
Version < 6.12.97
Status affected
Version 6.18.25
Version < 6.18.40
Status affected
Version 7.0.2
Version < 7.1
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 7.1
Status affected
Version 0
Version < 7.1
Status unaffected
Version <= 6.6.*
Version 6.6.145
Status unaffected
Version <= 6.12.*
Version 6.12.97
Status unaffected
Version <= 6.18.*
Version 6.18.40
Status unaffected
Version <= 7.1.*
Version 7.1.5
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.65% 0.483
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/fb978d72052704c6b06c6b0f129fcd60b77169f5
https://git.kernel.org/stable/c/93d4d46bf9d442a12ea87278049ec416962c627f
https://git.kernel.org/stable/c/5a5ac2852cd326529d02f778bc1aa6184701f4d7
https://git.kernel.org/stable/c/ed98719be41389d416953b8ef9f07a07dfea6b2b
https://git.kernel.org/stable/c/38637163501fd9e2f684b8cd275d0db5d79f37c6