ksmbd: fix use-after-free by using call_rcu() for oplock_info
Published May 8, 2026
9.8
CRITICALCVSS 3.1
EPSS 0.65%
Description
ksmbd currently frees oplock_info immediately using kfree(), even though it is accessed under RCU read-side critical sections in places like opinfo_get() and proc_show_files().
Since there is no RCU grace period delay between nullifying the pointer and freeing the memory, a reader can still access oplock_info structure after it has been freed. This can leads to a use-after-free especially in opinfo_get() where atomic_inc_not_zero() is called on already freed memory.
Fix this by switching to deferred freeing using call_rcu().
Affected products
-
Affected
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
-
Affected
- ≥ 6.12.25, < 6.12.78
- ≥ 6.14.4, < 6.15
- ≥ 6.6.88, < 6.6.130
-
Affected
- 6.15
Unaffected
- ≥ 0, < 6.15
- ≥ 6.12.78, ≤ 6.12.*
- ≥ 6.18.19, ≤ 6.18.*
- ≥ 6.19.9, ≤ 6.19.*
- ≥ 6.6.130, ≤ 6.6.*
- 7.0
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Linux | Linux | unaffected | Affected
|
| Linux | Linux | unaffected | Affected
|
| Linux | Linux | affected | Affected
Unaffected
|
- ≥ 6.6.88 · < 6.6.130
- ≥ 6.12.25 · < 6.12.78
- ≥ 6.14.4 · < 6.15
- ≥ 6.15.1 · < 6.18.19
- ≥ 6.19 · < 6.19.9
- 6.15
- 6.15
- 6.15
- 6.15
- 6.15
- 6.15
- 7.0
- 7.0
- 7.0
No data.
Red Hat Enterprise Linux 10
kernel
Not affected
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (11)
- https://access.redhat.com/security/cve/CVE-2026-43376 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2468218 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-28682 Advisory
- https://git.kernel.org/stable/c/08aa9f3c8cf4d0bee44df540dfe34e8d64069f2c Patch
- https://git.kernel.org/stable/c/1d6abf145615dbfe267ce3b0a271f95e3780e18e Patch
- https://git.kernel.org/stable/c/1dfd062caa165ec9d7ee0823087930f3ab8a6294 Patch
- https://git.kernel.org/stable/c/302fef75512b2c8329a3f5efab1ae7ba2562387a Patch
- https://git.kernel.org/stable/c/ce8507ee82c888126d8e7565e27c016308d24cde Patch
- https://lore.kernel.org/linux-cve-announce/2026050831-CVE-2026-43376-e32d@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2026-43376
- https://www.cve.org/CVERecord?id=CVE-2026-43376
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
GitHub
No data