ksmbd: serialize QUERY_DIRECTORY requests per file
Published Jul 25, 2026
9.8
CRITICALCVSS 3.1
EPSS 0.70%
Description
smb2_query_dir() stores a pointer to its stack-allocated private data in the ksmbd_file readdir_data. Concurrent QUERY_DIRECTORY requests using the same file handle can overwrite this pointer while an iterate_dir() callback is still using it, resulting in a stack use-after-free.
Add a per-file mutex and hold it while accessing the shared directory enumeration state. The lock covers scan restart, dot entry state, readdir_data setup and iteration, and response construction. This prevents another request from replacing readdir_data.private before the current request has finished using it and also serializes the shared file position.
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 5.15StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<5.15
- Version 6.1.178StatusunaffectedConstraints<=6.1.*
- Version 6.12.96StatusunaffectedConstraints<=6.12.*
- Version 6.18.39StatusunaffectedConstraints<=6.18.*
- Version 6.6.145StatusunaffectedConstraints<=6.6.*
- Version 7.1.4StatusunaffectedConstraints<=7.1.*
- Version 7.2StatusunaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux | unaffected |
| |||||||||||||||||||||||||||
| Linux | Linux | affected |
|
- ≥ 5.15 · < 6.1.178
- ≥ 6.2 · < 6.6.145
- ≥ 6.7 · < 6.12.96
- ≥ 6.13 · < 6.18.39
- ≥ 6.19 · < 7.1.4
No data.
Red Hat Enterprise Linux 10
kernel
Not affected
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Not affected
Red Hat Hardened Images
erlang27
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Not affected | n/a |
| Red Hat Hardened Images | erlang27 | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (12)
- https://access.redhat.com/security/cve/CVE-2026-64397 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2507300 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-48941 Advisory
- https://git.kernel.org/stable/c/1426fd79102539bc0ab5c8fced047ad4313b9908 Patch
- https://git.kernel.org/stable/c/2a64dbf9c739ddf7a25a066507597bf89f8f73d2 Patch
- https://git.kernel.org/stable/c/64dac2d486ec1eb18dc00968b16a230b6b75ec24 Patch
- https://git.kernel.org/stable/c/a1d5d31cad593ea5e1b637f2f39c9ef6d09d1199 Patch
- https://git.kernel.org/stable/c/be6d26bf27499977c746abc163659915082348d8 Patch
- https://git.kernel.org/stable/c/fd22b039a5a05bc1d6818e9dcd1001fb432a829d Patch
- https://lore.kernel.org/linux-cve-announce/2026072529-CVE-2026-64397-7e0d@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2026-64397
- https://www.cve.org/CVERecord?id=CVE-2026-64397
Change history (0)
No recorded changes yet.