CVE-2026-64396: ksmbd: fix UAF of struct file_lock in SMB2_LOCK deferred-lock cancellation
Greg Kroah-Hartman <[email protected]> Sat, 25 Jul 2026 10:50:13 +0200
| Newsgroups | org.kernel.vger.linux-cve-announce |
|---|---|
| Message-ID | <2026072528-CVE-2026-64396-7ca2@gregkh> |
From: Greg Kroah-Hartman <[email protected]> Description =========== In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix UAF of struct file_lock in SMB2_LOCK deferred-lock cancellation When a blocking byte-range lock request is deferred in the FILE_LOCK_DEFERRED path, ksmbd registers the asynchronous work into the connection's async_requests list via setup_async_work(). The cancel callback smb2_remove_blocked_lock() holds a reference to the flock. If the lock waiter is subsequently woken up but the work state is no longer KSMBD_WORK_ACTIVE (e.g., due to a concurrent cancellation), the cleanup path calls locks_free_lock(flock) without dequeuing the work from the async_requests list. Concurrently, smb2_cancel() walks the list under conn->request_lock and invokes the cancel callback, which then dereferences the already freed 'flock'. This leads to a slab-use-after-free inside __wake_up_common. Fix this by restructuring the cleanup logic after the worker returns from ksmbd_vfs_posix_lock_wait(). Move list_del(&smb_lock->llist) and release_async_work(work) to the top of the cleanup block. This guarantees that the async work is completely dequeued and serialized under conn->request_lock before locks_free_lock(flock) is called, rendering the flock unreachable for any concurrent smb2_cancel(). The Linux kernel CVE team has assigned CVE-2026-64396 to this issue. Affected and fixed versions =========================== Fixed in 6.1.178 with commit 367c42a611fe488b7b03f1f6737f4dee0e8b20a2 Fixed in 6.6.145 with commit 7703fd9aba1f2483c8e55f9ff73b7663e0761ed9 Fixed in 6.12.96 with commit 463bbd79698513af4dad50fe1c573825f297ca2e Fixed in 6.18.39 with commit 5aa1cb01155f96824003baf7997cdf1f150caba3 Fixed in 7.1.4 with commit 5c75275c0fc9a2deb0d8f5604edcb16f288171c8 Fixed in 7.2-rc1 with commit d20d1c8ba5765d1d12eefc0aee6385ab3f240e1e Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-64396 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: fs/smb/server/smb2pdu.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/367c42a611fe488b7b03f1f6737f4dee0e8b20a2 https://git.kernel.org/stable/c/7703fd9aba1f2483c8e55f9ff73b7663e0761ed9 https://git.kernel.org/stable/c/463bbd79698513af4dad50fe1c573825f297ca2e https://git.kernel.org/stable/c/5aa1cb01155f96824003baf7997cdf1f150caba3 https://git.kernel.org/stable/c/5c75275c0fc9a2deb0d8f5604edcb16f288171c8 https://git.kernel.org/stable/c/d20d1c8ba5765d1d12eefc0aee6385ab3f240e1e