KernelScan.io

HIGH Introduced in 5.15

ksmbd BlockedLock UAF

CVE-2026-90155

CVSS 7.5 / 10.0 KernelScan AI

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

01

In the Linux kernel, the following vulnerability has been resolved: ksmbd: detach blocked lock requests before freeing A file_lock retained by ksmbd for byte-range lock bookkeeping can still be part of the VFS blocked-request graph. In particular, the VFS can chain a new waiter below an already blocked request through flc_blocked_requests. The ksmbd_file reference count does not cover that graph. Both __ksmbd_close_fd() and the cross-request unlock path free these retained file_lock objects directly. If a dependent waiter is still attached, locks_release_private() hits BUG_ON(!list_empty(&flc->flc_blocked_requests)). The same lifetime mismatch can leave a freed ksmbd_lock reachable through its request-local llist. Detach the file_lock from the blocked-request graph before freeing it in the close, cross-request unlock, and rollback paths. locks_delete_block() also wakes requests chained below the object. Remove llist when a completed lock is published so a globally visible ksmbd_lock no longer points into the submitting worker's stack.

02

Engine v0.6.0

Risk summary

An authenticated remote SMB client can trigger a use-after-free in the ksmbd in-kernel SMB server by exploiting a lifetime mismatch between retained byte-range lock objects and the VFS blocked-request graph. This can cause a kernel panic or potentially allow arbitrary kernel memory corruption, leading to code execution on the host running the SMB server.

Affectedfs/smb/server/smb2pdu.c, fs/smb/server/vfs_cache.c (ksmbd)

Vulnerability analysis

ksmbd retains file lock objects for byte-range lock bookkeeping, but those objects can still be chained into the VFS blocked-request graph when another lock request waits below them. When ksmbd frees a retained lock during file close, cross-request unlock, or rollback, it does so without first detaching the object from that graph, leaving freed memory reachable through the VFS's blocked-request list and triggering a kernel panic. The same lifetime gap leaves a freed lock structure reachable through a per-request list. The fix detaches each lock from the blocked-request graph and wakes dependent waiters before freeing, and removes the per-request list entry once a lock is published so a globally visible lock object no longer references a submitting worker's stack. Any SMB client with network access to the ksmbd service and valid credentials to open files and issue lock requests can trigger this vulnerability; no local privileges on the server are needed.

03

BranchIntroducedFixed inPatch commit
7.25.157.2.6514a0b2bc949
mainline5.157.3-rc1215e8816b1ac