CVE-2026-72492
CVE CVE-2026-72492EUVD EUVD-2026-59391Published 2026-08-15T05:57:26.000ZLast changed 2026-08-17T05:44:53.000ZCVSS 8.8
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in same_client_has_lease() same_client_has_lease() returns an opinfo pointer from ci->m_op_list after dropping ci->m_lock without taking a reference. smb_grant_oplock() then dereferences that pointer in copy_lease() and when checking breaking_cnt. A concurrent close can remove the old lease from ci->m_op_list and drop the last reference before the caller uses the returned pointer, leading to a use-after-free. Take a reference when same_client_has_lease() selects an existing lease, drop any previous match while scanning, and release the returned reference in smb_grant_oplock() after copying the lease state.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux patch: 6.1.178; e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 <7c3264d273d524aa6adcce23c01087271f13586f; e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 <09634cd055d9bd8dd167995ea52bcd8028dd5dac; e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 <0ff82a9cf9312678d8bc4edeef0b6e82659ac12a; patch: 7.2; e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 <79c7c59bb519db6f5a2a151965e825ec725614cc; e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 <aaa3bb2bbf2ccbfea9e4e0b9dabf3afc60b50cd0; 5.15; e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 <35d3d6ff2bc1e7aaecb15d5377ebbd6227acae0d; patch: 5.15.212; e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 <65b655f65c3ca1ab5d598d3832bb0ff531725858; patch: 6.12.97; patch: 0; patch: 6.18.40; patch: 7.1.5; patch: 6.6.145
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.