HIGH Introduced in 5.15
ksmbd Oplock Race
CVE-2026-90167
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
01Description
In the Linux kernel, the following vulnerability has been resolved: ksmbd: serialize oplock close with pending break ownership close may abort an in-flight oplock break while another breaker already holds an opinfo reference. Releasing pending_break wakes that waiter, but without serializing the close transition with bit acquisition it can become a new break owner through the test_and_set_bit() fast path. It can then overwrite OPLOCK_CLOSING with OPLOCK_ACK_WAIT and continue a break for a dying opinfo. Make OPLOCK_CLOSING terminal once the opinfo is removed from the inode list. Serialize that transition, pending_break acquisition, and OPLOCK_ACK_WAIT setup with an opinfo state lock. A breaker which loses the race releases its ownership and returns -ENOENT. Explicitly wake pending_break waiters during close so they can observe the terminal state. Also prevent ACK and timeout paths from replacing OPLOCK_CLOSING with OPLOCK_STATE_NONE.
02KernelScan AI Analysis
Risk summary
A race condition in the kernel SMB server's oplock handling allows an authenticated network client to corrupt oplock state during file close, potentially leading to kernel memory corruption or a crash. The vulnerability requires a narrow timing window between close and oplock-break operations but is reachable by any valid SMB client over the network.
Vulnerability analysis
A race condition in the kernel SMB server's oplock (opportunistic lock) handling allows a file close to corrupt the state of an in-flight oplock break. When a file is closed while an oplock break is pending, the close path releases break ownership without proper serialization against a concurrent breaker thread. That breaker can then wake up, acquire break ownership, and continue operating on an oplock structure that is being torn down — leading to use of stale state and potential memory corruption. The fix adds a dedicated spinlock to serialize oplock state transitions, makes the closing state terminal so no other state can override it, and ensures losing racers cleanly abort with an error. An authenticated SMB client reachable over the network can trigger this by performing file operations that conflict with another client's oplock, requiring valid SMB credentials and a narrow timing window.
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| 7.2 | 5.15 | 7.2.6 | 5f97bac88bfb |
| mainline | 5.15 | 7.3-rc1 | b0148dc5625d |