KernelScan.io

CRITICAL

ksmbd OplockBreak UAF

CVE-2026-80926

CVSS 9.8 / 10.0 NVD

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

KernelScan AI7.5HIGH

01

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in oplock break notification smb2_oplock_break_noti() reads opinfo->conn without any lock and dereferences it after two allocations which may sleep. When the durable handle owning the oplock is disconnected, session_fd_check() clears opinfo->conn and drops its conn reference under ci->m_lock, and the last ksmbd_conn_put() frees the connection. A break triggered by another connection that races with the teardown can then resurrect the freed connection: ksmbd_conn_get() is a plain atomic_inc, and the queued break work later dereferences the stale conn via ksmbd_conn_write(), a use-after-free reachable by any authenticated client holding a durable batch oplock. Thread the caller's inode into the notification path instead of taking a new reference on it. Every caller of oplock_break() already holds a live ksmbd_file (or an explicit ksmbd_inode_lookup_lock() reference, in the parent lease break paths) on the inode that owns the break target's oplock list, so ci cannot be freed during the call, and its lock can be taken without dereferencing opinfo->o_fp, which a concurrent close may free. Select and pin the connection under ci->m_lock, the same lock session_fd_check() and ksmbd_reopen_durable_fd() use to update opinfo->conn, so a concurrent detach either loses the race to the clear or keeps the connection alive until the notification work releases it. Transfer the reference to the work item and release it on allocation failures.

02

Engine v0.6.0

Risk summary

An authenticated SMB client can trigger a use-after-free in the kernel SMB server (ksmbd) by racing a durable handle disconnect with an oplock break notification from another connection. This leads to heap corruption of a freed connection object, potentially allowing code execution or kernel panic. Any device running ksmbd with network-accessible SMB shares is at risk.

Affectedfs/smb/server/oplock.c (ksmbd)

Vulnerability analysis

When an SMB client holds a durable batch oplock and its connection is disconnected, the teardown path clears the oplock's connection pointer and drops the connection reference. A concurrent oplock break notification triggered by another connection can read that connection pointer without holding the protecting lock, then take a reference on it after sleeping allocations — by which point the connection may already have been freed. The queued break work later dereferences the stale connection, causing a use-after-free. The fix threads the caller's inode reference into the notification path so the inode lock can be taken safely, and pins the connection under that lock before any allocations occur, transferring the reference to the work item and releasing it on failure. Any authenticated SMB client holding a durable batch oplock can reach this code path over the network.

03

BranchIntroducedFixed inPatch commit
6.126.12.946.12.1115de0527f7824
7.2—7.2.5—
mainline—7.3-rc2—
7.07.0.137.10e753899627b
6.66.6.1436.78cc98db4fc59
6.186.18.366.18.51c8279ae8df68