CRITICAL Introduced in 6.9
ksmbd DurableReconnect UAF
CVE-2026-53010
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
KernelScan AI7.1HIGH
01Description
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in smb2_open during durable reconnect In smb2_open, the call to ksmbd_put_durable_fd(fp) drops the reference to the durable file descriptor early during the durable reconnect process. If an error occurs subsequently (eg, ksmbd_iov_pin_rsp fails) or a scavenger accesses the file, it leads to a use-after-free when accessing fp properties (eg fp->create_time). Move the single put to the end of the function below err_out2 so fp stays valid until smb2_open returns.
02KernelScan AI Analysis
Risk summary
A use-after-free vulnerability in the ksmbd kernel SMB server allows an authenticated SMB client to trigger memory corruption during a durable handle reconnect. Because ksmbd_put_durable_fd() drops the reference to the durable file descriptor early while smb2_open() continues to access fp properties, subsequent code paths (including error handling and scavenger activity) can reference freed heap memory. This can leak kernel pointer data from the freed object (C:Low) and enable kernel memory corruption (I:High) or a kernel panic (A:High). The bug is reachable over the network by any authenticated SMB user connecting to a ksmbd share.
Vulnerability analysis
The vulnerability is a use-after-free in smb2_open() within the ksmbd kernel SMB2 server. During a durable handle reconnect, ksmbd_put_durable_fd(dh_info.fp) was called at multiple early points inside the reconnected block (after smb2_check_durable_oplock, ksmbd_reopen_durable_fd, ksmbd_override_fsids, and after ksmbd_vfs_getattr). After the reference drop, the function continues to use the fp pointer to build responses and handle errors. If an error occurs subsequently (e.g., ksmbd_iov_pin_rsp fails) or a scavenger thread frees the object, the kernel accesses freed fp properties such as fp->create_time and fp->filp, constituting a use-after-free. The fix consolidates the single ksmbd_put_durable_fd call to the end of the function at err_out2, guarded by dh_info.reconnected, ensuring fp remains valid for the entire duration of smb2_open. The attack surface is the SMB2 network protocol: any authenticated client can initiate a durable reconnect request, and the premature put leaves a dangling pointer that is accessed on later success or error paths.
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| 6.12 | 6.9 | 6.12.110 | 4db3dcac84c2 |
| 7.0 | 6.9 | 7.0.10 | 97a0cd55283b |
| mainline | 6.9 | 7.1 | 1baff47b81f9 |
| 6.18 | 6.9 | 6.18.33 | ce2e164c1c51 |
| 6.6 | 6.6.32 | 6.6.157 | f0ff7f12398e |