CVE-2026-80926
CVE CVE-2026-80926EUVD EUVD-2026-76248Veröffentlicht 2026-09-11T19:37:29.000ZZuletzt geändert 2026-09-13T06:28:07.000ZCVSS 9.8
Was das Advisory beschreibt
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in oplock break notification smb2_oplock_break_noti() reads opinfo->conn without any lock and dereferences it after two allocations which may sleep. When the durable handle owning the oplock is disconnected, session_fd_check() clears opinfo->conn and drops its conn reference under ci->m_lock, and the last ksmbd_conn_put() frees the connection. A break triggered by another connection that races with the teardown can then resurrect the freed connection: ksmbd_conn_get() is a plain atomic_inc, and the queued break work later dereferences the stale conn via ksmbd_conn_write(), a use-after-free reachable by any authenticated client holding a durable batch oplock. Thread the caller's inode into the notification path instead of taking a new reference on it. Every caller of oplock_break() already holds a live ksmbd_file (or an explicit ksmbd_inode_lookup_lock() reference, in the parent lease break paths) on the inode that owns the break target's oplock list, so ci cannot be freed during the call, and its lock can be taken without dereferencing opinfo->o_fp, which a concurrent close may free. Select and pin the connection under ci->m_lock, the same lock session_fd_check() and ksmbd_reopen_durable_fd() use to update opinfo->conn, so a concurrent detach either loses the race to the clear or keeps the connection alive until the notification work releases it. Transfer the reference to the work item and release it on allocation failures.
Quelle: EUVD (ENISA), im Wortlaut der Meldung.
Produkte, die das Advisory nennt
Diese Angaben stammen aus der Meldung selbst, nicht aus einer Prüfung durch uns.
- Linux — Linux patch: 7.2.5; 7.0.13 <7.1; 7.1; 6.6.143 <6.7; patch: 7.3-rc2; 945a86b21b40fb17183f5b27461baa6f03e2467f; b003086d76968298f22e7cf62239833b5a3a06b1 <8cc98db4fc590e6c7d9db6529320982ee16c5d1d; 1ff58dcfcab434ebb51649da33774fbb8e1f7b67; patch: 6.18.51; 6.18.36 <6.18.51; e735dbd489e3ea02be78dba991056fe1138be51e <c8279ae8df68cce9cd3b785e85f7a86c80a46e78; 6.12.94 <6.13; 75e33deda658c1ab3a9336cbdb1436536f9b3660; b003086d76968298f22e7cf62239833b5a3a06b1 <0e753899627b5e28a9fea8bca98262a6f65a2452; patch: 0
Die genannten Versionen sind die Angabe der Meldung. Patchlage vergleicht keine Versionsnummern und leitet aus ihnen keine Aussage ab — welche Version installiert ist, muss ein Mensch nachsehen.
Im Produktkatalog geführt
Für diese Produkte kann ein Bestand in Patchlage erfasst werden. Ein Advisory dazu erscheint am Morgen danach im Lagebericht.
- Linux — Linux
Betrifft das einen Ihrer Kundenbestände?
Diese Seite kann die Frage nicht beantworten — sie kennt Ihren Bestand nicht. Wer seine Umgebungen erfasst hat, bekommt die Antwort am Morgen nach der Veröffentlichung, zusammen mit einem Absatz, den er unverändert an den Kunden weitergeben kann.
28 Tage testenPatchlage meldet Treffer und Verdachtsfälle. Zu allem anderen sagt dieses System nichts — weder diese Seite noch der Lagebericht behauptet je, dass ein Bestand sicher ist.