CVE-2026-31444
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: fix use-after-free and NULL deref in smbgrantoplock()
smbgrantoplock() has two issues in the oplock publication sequence:
- opinfo is linked into ci->moplist (via opinfo_add) before
addleasegloballist() is called. If addleasegloballist()
fails (kmalloc returns NULL), the error path frees the opinfo
via _freeopinfo() while it is still linked in ci->moplist.
Concurrent moplist readers (opinfogetlist, or direct iteration
in smbbreakalllevIIoplock) dereference the freed node.
- opinfo->ofp is assigned after addleasegloballist() publishes
the opinfo on the global lease list. A concurrent
findsamelease_key() can walk the lease list and dereference
opinfo->ofp->fci while o_fp is still NULL.
Fix by restructuring the publication sequence to eliminate post-publish
failure:
- Set opinfo->o_fp before any list publication (fixes NULL deref).
- Preallocate leasetable via allocleasetable() before opinfoadd()
so addleaseglobal_list() becomes infallible after publication.
- Keep the original moplist publication order (opinfo_add before
lease list) so concurrent opens via sameclienthas_lease() and
opinfogetlist() still see the in-flight grant.
- Use opinfoput() instead of freeopinfo() on err_out so that
the RCU-deferred free path is used.
This also requires splitting addleaseglobal_list() to take a
preallocated lease_table and changing its return type from int to void,
since it can no longer fail.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://git.kernel.org/stable/c/48623ec358c1c600fa1e38368746f933e0f1a617, https://git.kernel.org/stable/c/6d7e5a918c1d0aad06db0e17677b66fc9a471021, https://git.kernel.org/stable/c/7de55bba69cbf0f9280daaea385daf08bc076121, https://git.kernel.org/stable/c/9e785f004cbc56390479b77375726ea9b0d1a8a6, https://git.kernel.org/stable/c/a5c6f6d6ceefed2d5210ee420fb75f8362461f46, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/31xxx/CVE-2026-31444.json, https://nvd.nist.gov/vuln/detail/CVE-2026-31444, https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git