{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-90162","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.790Z","datePublished":"2026-09-17T16:06:53.136Z","dateUpdated":"2026-09-18T17:53:30.727Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-18T17:53:30.727Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: defer publishing granted locks to prevent UAF/double-free race\n\nIn smb2_lock(), mid-batch granted locks are published to connection-wide\n(conn->lock_list) and file-wide (fp->lock_list) lists immediately upon\nvfs_lock_file() success, while also remaining tracked on the stack-local\nrollback_list.\n\nIf a subsequent element in the same SMB2_LOCK request array fails\nvalidation or execution, the thread jumps to out: and walks\nrollback_list to undo previously granted locks. However, because the\ngranted lock was already published to conn->lock_list, a concurrent\nUNLOCK request on the same connection can find the lock object and\nkfree() it before the rollback loop executes.\n\nWhen the granting thread subsequently walks rollback_list, it\ndereferences and frees the already-freed ksmbd_lock structure, resulting\nin a Use-After-Free and Double-Free (on both ksmbd_lock and struct\nfile_lock).\n\nFix this by deferring the publication of granted locks to\nconn->lock_list and fp->lock_list until after the entire array of lock\nelements has been processed without error. Mid-batch grants remain\ntracked exclusively on the request-local rollback_list until the whole\nbatch succeeds, eliminating the race window."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:N - The attacker-controlled data is the SMB2 LOCK request (struct smb2_lock_req lock elements: Offset, Length, Flags) received on TCP/445 by ksmbd_conn_handler_loop(), queued with queue_ksmbd_work(), and dispatched to smb2_lock() via conn->cmds[SMB2_LOCK_HE]; the racing free is a second SMB2 LOCK with SMB2_LOCKFLAG_UNLOCK on the same FID.\nAC:L - The attacker drives both sides: smb2_lock() publishes a granted ksmbd_lock onto conn->lock_list after vfs_lock_file() succeeds for lock element 0, then a later element in the same LockCount>1 array fails (cmd<0, missing SMB2_LOCKFLAG_MASK, or overlap) and walks rollback_list, while a concurrent SMB2 LOCK UNLOCK on ksmbd-io (WQ_PERCPU) kfree()s that object; the race is retryable.\nPR:L - SMB2_LOCK is not in the smb2_check_user_session() pre-auth skip list (only NEGOTIATE/SESSION_SETUP/ECHO); it requires SMB2_SESSION_VALID, smb2_get_ksmbd_tcon() for a tree id, and ksmbd_lookup_fd_slow() after smb2_open(). An ordinary authenticated share user suffices; this is not a pre-auth handshake.\nUI:N - The attacker completes SESSION_SETUP, TREE_CONNECT and CREATE on their own ksmbd TCP connection, then sends the multi-element SMB2 LOCK and concurrent UNLOCK; no victim mount, click, or administrator action is required.\nS:U - The UAF and double-free of ksmbd_lock and struct file_lock occur in the ksmbd-io worker on the host that accepted the SMB session and do not cross a VM, guest-to-host, or IOMMU/DMA boundary.\nC:H - UNLOCK's kfree(cmp_lock) leaves rollback reading smb_lock->start, smb_lock->end, smb_lock->conn and smb_lock->fl from a freed ksmbd_lock; reclaiming that slab or the associated file_lock_cache object with attacker-controlled contents yields an arbitrary kernel read.\nI:H - The same rollback path list_del()s smb_lock->flist and smb_lock->clist on the freed object, then locks_free_lock(smb_lock->fl) and kfree(smb_lock) after UNLOCK already freed both, giving a double-free and list_del write primitive for heap corruption and control-flow hijack.\nA:H - Dereferencing the freed ksmbd_lock (including spin_lock on smb_lock->conn->llist_lock) and double-freeing ksmbd_lock/file_lock oops or panic the ksmbd-io worker; the LOCK/UNLOCK pair can be repeated to crash the host."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/smb/server/smb2pdu.c"],"versions":[{"version":"e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9","lessThan":"a1d26dfb32919088e3638dca01068df3c4507433","status":"affected","versionType":"git"},{"version":"e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9","lessThan":"29f74f0f2e6df3b393b7b66e810136d0c64e3c59","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/smb/server/smb2pdu.c"],"versions":[{"version":"5.15","status":"affected"},{"version":"0","lessThan":"5.15","status":"unaffected","versionType":"semver"},{"version":"7.2.6","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.15","versionEndExcluding":"7.2.6"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.15","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/a1d26dfb32919088e3638dca01068df3c4507433"},{"url":"https://git.kernel.org/stable/c/29f74f0f2e6df3b393b7b66e810136d0c64e3c59"}],"title":"ksmbd: defer publishing granted locks to prevent UAF/double-free race","x_generator":{"engine":"bippy-1.2.0"}}}}