Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

CVE-2026-31444

ksmbd: fix use-after-free and NULL deref in smb_grant_oplock()
Back to all
CVE

CVE-2026-31444

ksmbd: fix use-after-free and NULL deref in smb_grant_oplock()

In the Linux kernel, the following vulnerability has been resolved:

ksmbd: fix use-after-free and NULL deref in smbgrantoplock()

smbgrantoplock() has two issues in the oplock publication sequence:

  1. opinfo is linked into ci->moplist (via opinfo_add) before

   addleasegloballist() is called.  If addleasegloballist()

   fails (kmalloc returns NULL), the error path frees the opinfo

   via _freeopinfo() while it is still linked in ci->moplist.

   Concurrent moplist readers (opinfogetlist, or direct iteration

   in smbbreakalllevIIoplock) dereference the freed node.

  1. opinfo->ofp is assigned after addleasegloballist() publishes

   the opinfo on the global lease list.  A concurrent

   findsamelease_key() can walk the lease list and dereference

   opinfo->ofp->fci while o_fp is still NULL.

Fix by restructuring the publication sequence to eliminate post-publish

failure:

  • Set opinfo->o_fp before any list publication (fixes NULL deref).
  • Preallocate leasetable via allocleasetable() before opinfoadd()

  so addleaseglobal_list() becomes infallible after publication.

  • Keep the original moplist publication order (opinfo_add before

  lease list) so concurrent opens via sameclienthas_lease() and

  opinfogetlist() still see the in-flight grant.

  • Use opinfoput() instead of freeopinfo() on err_out so that

  the RCU-deferred free path is used.

This also requires splitting addleaseglobal_list() to take a

preallocated lease_table and changing its return type from int to void,

since it can no longer fail.

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
9.8
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
0
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
-

Related Resources

No items found.

References

https://git.kernel.org/stable/c/48623ec358c1c600fa1e38368746f933e0f1a617, https://git.kernel.org/stable/c/6d7e5a918c1d0aad06db0e17677b66fc9a471021, https://git.kernel.org/stable/c/7de55bba69cbf0f9280daaea385daf08bc076121, https://git.kernel.org/stable/c/9e785f004cbc56390479b77375726ea9b0d1a8a6, https://git.kernel.org/stable/c/a5c6f6d6ceefed2d5210ee420fb75f8362461f46, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/31xxx/CVE-2026-31444.json, https://nvd.nist.gov/vuln/detail/CVE-2026-31444, https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Severity

9.8

CVSS Score
0
10

Basic Information

Base CVSS
9.8
EPSS Probability
0.0045%
EPSS Percentile
0.36099%
Introduced Version
302fef75512b2c8329a3f5efab1ae7ba2562387a,08aa9f3c8cf4d0bee44df540dfe34e8d64069f2c,1d6abf145615dbfe267ce3b0a271f95e3780e18e,ce8507ee82c888126d8e7565e27c016308d24cde,1dfd062caa165ec9d7ee0823087930f3ab8a6294,6.6.130,6.12.78,6.18.19,6.19.9,0
Fix Available
9e785f004cbc56390479b77375726ea9b0d1a8a6,7de55bba69cbf0f9280daaea385daf08bc076121,a5c6f6d6ceefed2d5210ee420fb75f8362461f46,6d7e5a918c1d0aad06db0e17677b66fc9a471021,48623ec358c1c600fa1e38368746f933e0f1a617,6.6.131,6.12.80,6.18.21,6.19.11

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading