CVE-2026-64396: ksmbd: fix UAF of struct file_lock in SMB2_LOCK deferred-lock cancellation

Greg Kroah-Hartman <[email protected]> Sat, 25 Jul 2026 10:50:13 +0200
Newsgroups org.kernel.vger.linux-cve-announce
Message-ID <2026072528-CVE-2026-64396-7ca2@gregkh>
From: Greg Kroah-Hartman <[email protected]>

Description
===========

In the Linux kernel, the following vulnerability has been resolved:

ksmbd: fix UAF of struct file_lock in SMB2_LOCK deferred-lock cancellation

When a blocking byte-range lock request is deferred in the
FILE_LOCK_DEFERRED path, ksmbd registers the asynchronous work into
the connection's async_requests list via setup_async_work(). The cancel
callback smb2_remove_blocked_lock() holds a reference to the flock.

If the lock waiter is subsequently woken up but the work state is no
longer KSMBD_WORK_ACTIVE (e.g., due to a concurrent cancellation), the
cleanup path calls locks_free_lock(flock) without dequeuing the work from
the async_requests list. Concurrently, smb2_cancel() walks the list
under conn->request_lock and invokes the cancel callback, which then
dereferences the already freed 'flock'. This leads to a slab-use-after-free
inside __wake_up_common.

Fix this by restructuring the cleanup logic after the worker returns
from ksmbd_vfs_posix_lock_wait(). Move list_del(&smb_lock->llist) and
release_async_work(work) to the top of the cleanup block. This guarantees
that the async work is completely dequeued and serialized under
conn->request_lock before locks_free_lock(flock) is called, rendering
the flock unreachable for any concurrent smb2_cancel().

The Linux kernel CVE team has assigned CVE-2026-64396 to this issue.


Affected and fixed versions
===========================

	Fixed in 6.1.178 with commit 367c42a611fe488b7b03f1f6737f4dee0e8b20a2
	Fixed in 6.6.145 with commit 7703fd9aba1f2483c8e55f9ff73b7663e0761ed9
	Fixed in 6.12.96 with commit 463bbd79698513af4dad50fe1c573825f297ca2e
	Fixed in 6.18.39 with commit 5aa1cb01155f96824003baf7997cdf1f150caba3
	Fixed in 7.1.4 with commit 5c75275c0fc9a2deb0d8f5604edcb16f288171c8
	Fixed in 7.2-rc1 with commit d20d1c8ba5765d1d12eefc0aee6385ab3f240e1e

Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.

Unaffected versions might change over time as fixes are backported to
older supported kernel versions.  The official CVE entry at
	https://cve.org/CVERecord/?id=CVE-2026-64396
will be updated if fixes are backported, please check that for the most
up to date information about this issue.


Affected files
==============

The file(s) affected by this issue are:
	fs/smb/server/smb2pdu.c


Mitigation
==========

The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes.  Individual
changes are never tested alone, but rather are part of a larger kernel
release.  Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all.  If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
	https://git.kernel.org/stable/c/367c42a611fe488b7b03f1f6737f4dee0e8b20a2
	https://git.kernel.org/stable/c/7703fd9aba1f2483c8e55f9ff73b7663e0761ed9
	https://git.kernel.org/stable/c/463bbd79698513af4dad50fe1c573825f297ca2e
	https://git.kernel.org/stable/c/5aa1cb01155f96824003baf7997cdf1f150caba3
	https://git.kernel.org/stable/c/5c75275c0fc9a2deb0d8f5604edcb16f288171c8
	https://git.kernel.org/stable/c/d20d1c8ba5765d1d12eefc0aee6385ab3f240e1e