HIGH Introduced in 5.15
ksmbd BlockedLock UAF
CVE-2026-90155
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
01Description
In the Linux kernel, the following vulnerability has been resolved: ksmbd: detach blocked lock requests before freeing A file_lock retained by ksmbd for byte-range lock bookkeeping can still be part of the VFS blocked-request graph. In particular, the VFS can chain a new waiter below an already blocked request through flc_blocked_requests. The ksmbd_file reference count does not cover that graph. Both __ksmbd_close_fd() and the cross-request unlock path free these retained file_lock objects directly. If a dependent waiter is still attached, locks_release_private() hits BUG_ON(!list_empty(&flc->flc_blocked_requests)). The same lifetime mismatch can leave a freed ksmbd_lock reachable through its request-local llist. Detach the file_lock from the blocked-request graph before freeing it in the close, cross-request unlock, and rollback paths. locks_delete_block() also wakes requests chained below the object. Remove llist when a completed lock is published so a globally visible ksmbd_lock no longer points into the submitting worker's stack.
02KernelScan AI Analysis
Risk summary
An authenticated remote SMB client can trigger a use-after-free in the ksmbd in-kernel SMB server by exploiting a lifetime mismatch between retained byte-range lock objects and the VFS blocked-request graph. This can cause a kernel panic or potentially allow arbitrary kernel memory corruption, leading to code execution on the host running the SMB server.
Vulnerability analysis
ksmbd retains file lock objects for byte-range lock bookkeeping, but those objects can still be chained into the VFS blocked-request graph when another lock request waits below them. When ksmbd frees a retained lock during file close, cross-request unlock, or rollback, it does so without first detaching the object from that graph, leaving freed memory reachable through the VFS's blocked-request list and triggering a kernel panic. The same lifetime gap leaves a freed lock structure reachable through a per-request list. The fix detaches each lock from the blocked-request graph and wakes dependent waiters before freeing, and removes the per-request list entry once a lock is published so a globally visible lock object no longer references a submitting worker's stack. Any SMB client with network access to the ksmbd service and valid credentials to open files and issue lock requests can trigger this vulnerability; no local privileges on the server are needed.
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| 7.2 | 5.15 | 7.2.6 | 514a0b2bc949 |
| mainline | 5.15 | 7.3-rc1 | 215e8816b1ac |