KernelScan.io

HIGH

ksmbd ByteRange Bypass

CVE-2026-90176

CVSS 8.1 / 10.0 NVD

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

KernelScan AI8.0HIGH

01

In the Linux kernel, the following vulnerability has been resolved: ksmbd: Do not skip lock checks for single-byte ranges check_lock_range() uses inclusive ranges. Its callers pass the end offset as start + length - 1, so start == end represents a valid single-byte range rather than an empty range. The start == end shortcut therefore skips mandatory byte-range lock checks for one-byte reads, writes, copychunk operations and one-byte truncate ranges. A conflicting lock covering that byte is not checked and the operation is allowed to proceed. Remove the shortcut. The truncate size == inode->i_size case is already handled by only calling check_lock_range() when the new size differs from the current file size.

02

Engine v0.6.0

Risk summary

An authenticated SMB client can bypass mandatory byte-range lock checks for any single-byte read, write, copychunk, or truncate operation against a ksmbd server. This allows access to file regions that another client has explicitly locked, violating both data confidentiality and integrity. Any deployment exposing ksmbd over the network to multiple users is at risk.

Affectedfs/smb/server/vfs.c (ksmbd)

Vulnerability analysis

The in-kernel SMB server treats a file range where the start and end are the same as an empty region, but that actually represents a valid single-byte range. A shortcut added to avoid an integer underflow during truncates skips the mandatory lock conflict check for all one-byte reads, writes, copychunk operations, and truncates. An authenticated client can therefore read or write a byte that another client has locked, breaking file locking guarantees. The fix removes the shortcut; the original underflow issue is already avoided because the lock check is only run when the file size actually changes. Any network client that can authenticate to the ksmbd service can reach this flaw.

03

BranchIntroducedFixed inPatch commit
6.16.1.1606.1.188a89cc145832e
6.66.6.1206.6.157993e0158331d
6.126.12.646.12.110f751d6e39d4c
6.186.18.36.18.5284c2d8e807ac
7.2—7.2.607a9e289ff7e
mainline—7.3-rc1d40c24634fe0