{"id":"CVE-2026-72381","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-72381","summary":"ksmbd: fix use-after-free of fp->owner.name in durable handle owner check","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: fix use-after-free of fp->owner.name in durable handle owner check\n\nTwo concurrent SMB2 durable reconnects (DH2C/DHnC) on the same\npersistent_id race the fp->owner.name compare-read in\nksmbd_vfs_compare_durable_owner() against the kfree() in\nksmbd_reopen_durable_fd()'s reopen-success path. fp->owner.name is a\nstandalone kstrdup() buffer whose lifetime is independent of the fp\nrefcount, and the two sites share no lock: the compare reads the buffer\nwhile the reopen frees it, so the strcmp() can dereference freed memory.\n\nCommit 7ce4fc40018d (\"ksmbd: fix durable reconnect double-bind race in\nksmbd_reopen_durable_fd\") made the fp->conn claim atomic under\nglobal_ft.lock (closing the owner.name double-free and the ksmbd_file\nwrite-UAF), but the compare-read versus reopen-free pair was left\nunserialized.\n\n  BUG: KASAN: slab-use-after-free in strcmp+0x2c/0x80\n  Read of size 1 by task kworker\n    strcmp\n    ksmbd_vfs_compare_durable_owner\n    smb2_check_durable_oplock\n    smb2_open\n  Freed by task kworker:\n    kfree\n    ksmbd_reopen_durable_fd\n    smb2_open\n  Allocated by task kworker:\n    kstrdup\n    session_fd_check\n    smb2_session_logoff\n  The buggy address belongs to the cache kmalloc-8\n\nSerialize both sides of the race with fp->f_lock.  The global durable\nfile-table lock still protects the durable reconnect claim, but\nfp->owner.name is per-open state and does not need to block unrelated\ndurable table lookups or reconnects.  The teardown is left at its\nexisting location after the reopen-success point so that an __open_id()\nrollback still retains owner.name for a later legitimate reconnect to\nverify.","published":"2026-08-15T05:56:13.477Z","modified":"2026-08-18T03:56:42.678451675Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Linux","name":"Kernel","fixedVersion":"6.6.145"}],"fix":null,"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/38637163501fd9e2f684b8cd275d0db5d79f37c6"},{"type":"WEB","url":"https://git.kernel.org/stable/c/5a5ac2852cd326529d02f778bc1aa6184701f4d7"},{"type":"WEB","url":"https://git.kernel.org/stable/c/93d4d46bf9d442a12ea87278049ec416962c627f"},{"type":"WEB","url":"https://git.kernel.org/stable/c/ed98719be41389d416953b8ef9f07a07dfea6b2b"},{"type":"WEB","url":"https://git.kernel.org/stable/c/fb978d72052704c6b06c6b0f129fcd60b77169f5"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72381.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-72381"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-18T03:56:42.678451675Z"}}