PT-2026-94510 · Linux · Linux Kernel
CVE-2026-90162
·
Published
2026-09-17
·
Updated
2026-09-24
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A race condition exists in the
smb2 lock() function of the ksmbd module. When processing an SMB2 LOCK request array, locks are published to the connection-wide conn->lock list and file-wide fp->lock list immediately after vfs lock file() succeeds, while still being tracked on a stack-local rollback list. If a later element in the same request array fails, the system attempts to undo previously granted locks via the rollback list. However, a concurrent UNLOCK request can identify and free the lock object from the conn->lock list before the rollback occurs. This leads to a Use-After-Free and Double-Free condition affecting the ksmbd lock structure and struct file lock.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel