KernelScan.io

CRITICAL

ksmbd OplockBreak UAF

CVE-2026-68381

CVSS 9.8 / 10.0 NVD

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

KernelScan AI7.5HIGH

01

In the Linux kernel, the following vulnerability has been resolved: ksmbd: pin conn during async oplock break notification smb2_oplock_break_noti() and smb2_lease_break_noti() store a ksmbd_conn pointer in an async ksmbd_work and then queue that work on ksmbd-io. The work only increments conn->r_count, which prevents teardown from passing the pending-request wait after the increment, but it does not pin the struct ksmbd_conn object. If connection teardown races with an oplock break notification, the last conn reference can be dropped before the queued worker finishes. The worker then uses the freed conn in ksmbd_conn_write() and ksmbd_conn_r_count_dec(). Take a real conn reference when publishing the conn pointer to the async work item, and drop it after the notification work has decremented r_count. Apply the same lifetime rule to lease break notification, which uses the same work->conn pattern.

02

Engine v0.6.0

Risk summary

A remote SMB client can trigger a use-after-free in the in-kernel SMB server (ksmbd) by racing connection teardown with an oplock or lease break notification. The freed connection object is subsequently accessed by the queued worker, leading to kernel memory corruption that is potentially exploitable for code execution, privilege escalation, or a system crash. Any device running ksmbd with network exposure is at risk.

Affectedfs/smb/server/oplock.c (ksmbd)

Vulnerability analysis

When the kernel SMB server queues an asynchronous notification to break an oplock or lease, it stores a pointer to the connection object in the background work item without ensuring the object stays alive. If the client disconnects and connection teardown happens concurrently, the connection can be freed while the queued worker is still running. The worker then accesses memory that has already been freed while sending the notification and finishing its cleanup. The fix ensures the server takes a proper reference on the connection before handing it to the async work item, and only releases that reference after the worker has completely finished, so the connection remains valid for the entire task. Any authenticated SMB client connected to the server can reach this path by triggering an oplock or lease break and disconnecting at the right moment.

03

BranchIntroducedFixed inPatch commit
mainline—7.2-rc4—
6.126.12.206.12.101793e1c7041b9
6.66.6.846.6.1480f72fc9659d7
6.18—6.18.4214062c74e5b2
6.136.13.86.146ecb252efa0b
7.1—7.1.6aa5d8f3f96aa