CVE-2026-31444: ksmbd: fix use-after-free and NULL deref in smb_grant_oplock()
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: fix use-after-free and NULL deref in smbgrantoplock()
smbgrantoplock() has two issues in the oplock publication sequence:
1) opinfo is linked into ci->moplist (via opinfoadd) before addleasegloballist() is called. If addleasegloballist() fails (kmalloc returns NULL), the error path frees the opinfo via freeopinfo() while it is still linked in ci->moplist. Concurrent moplist readers (opinfogetlist, or direct iteration in smbbreakalllevIIoplock) dereference the freed node.
2) opinfo->ofp is assigned after addleasegloballist() publishes the opinfo on the global lease list. A concurrent findsameleasekey() can walk the lease list and dereference opinfo->ofp->fci while ofp is still NULL.
Fix by restructuring the publication sequence to eliminate post-publish failure:
- Set opinfo->ofp before any list publication (fixes NULL deref). - Preallocate leasetable via allocleasetable() before opinfoadd() so addleasegloballist() becomes infallible after publication. - Keep the original moplist publication order (opinfoadd before lease list) so concurrent opens via sameclienthaslease() and opinfogetlist() still see the in-flight grant. - Use opinfoput() instead of freeopinfo() on errout so that the RCU-deferred free path is used.
This also requires splitting addleasegloballist() to take a preallocated leasetable and changing its return type from int to void, since it can no longer fail.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-31444?
CVE-2026-31444 is rated as a critical vulnerability due to its potential to cause use-after-free and NULL dereference issues in the Linux kernel.
How do I fix CVE-2026-31444?
To mitigate CVE-2026-31444, update to the latest version of ksmbd in the Linux kernel that resolves the use-after-free and NULL deref vulnerabilities.
What systems are affected by CVE-2026-31444?
CVE-2026-31444 primarily affects the ksmbd component in the Linux kernel, specifically impacting systems running versions prior to the patch.
What are the consequences of exploiting CVE-2026-31444?
Exploitation of CVE-2026-31444 may allow an attacker to cause a denial of service or potentially execute arbitrary code on the affected system.
Who is responsible for addressing CVE-2026-31444?
The responsibility for addressing CVE-2026-31444 lies with system administrators and vendors who maintain the affected Linux kernel versions.