Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

CVE-2026-80926

ksmbd: fix use-after-free in oplock break notification
Back to all
CVE

CVE-2026-80926

ksmbd: fix use-after-free in oplock break notification

In the Linux kernel, the following vulnerability has been resolved:

ksmbd: fix use-after-free in oplock break notification

smb2oplockbreak_noti() reads opinfo->conn without any lock and

dereferences it after two allocations which may sleep.  When the

durable handle owning the oplock is disconnected, sessionfdcheck()

clears opinfo->conn and drops its conn reference under ci->m_lock, and

the last ksmbdconnput() frees the connection.  A break triggered by

another connection that races with the teardown can then resurrect the

freed connection: ksmbdconnget() is a plain atomic_inc, and the

queued break work later dereferences the stale conn via

ksmbdconnwrite(), a use-after-free reachable by any authenticated

client holding a durable batch oplock.

Thread the caller's inode into the notification path instead of taking

a new reference on it.  Every caller of oplock_break() already holds a

live ksmbdfile (or an explicit ksmbdinodelookuplock() reference,

in the parent lease break paths) on the inode that owns the break

target's oplock list, so ci cannot be freed during the call, and its

lock can be taken without dereferencing opinfo->o_fp, which a

concurrent close may free.  Select and pin the connection under

ci->mlock, the same lock sessionfd_check() and

ksmbdreopendurable_fd() use to update opinfo->conn, so a concurrent

detach either loses the race to the clear or keeps the connection

alive until the notification work releases it.  Transfer the reference

to the work item and release it on allocation failures.

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
9.8
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
0
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
-

Related Resources

No items found.

References

https://git.kernel.org/stable/c/0e753899627b5e28a9fea8bca98262a6f65a2452, https://git.kernel.org/stable/c/5de0527f782430b1109a447646e32033ad018a6a, https://git.kernel.org/stable/c/892f643b141aee3f7aa7c0fc61ddcb55c59f1996, https://git.kernel.org/stable/c/8cc98db4fc590e6c7d9db6529320982ee16c5d1d, https://git.kernel.org/stable/c/c8279ae8df68cce9cd3b785e85f7a86c80a46e78, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/80xxx/CVE-2026-80926.json, https://nvd.nist.gov/vuln/detail/CVE-2026-80926, https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Severity

9.8

CVSS Score
0
10

Basic Information

Base CVSS
9.8
EPSS Probability
0.00444%
EPSS Percentile
0.36633%
Introduced Version
945a86b21b40fb17183f5b27461baa6f03e2467f,1ff58dcfcab434ebb51649da33774fbb8e1f7b67,e735dbd489e3ea02be78dba991056fe1138be51e,b003086d76968298f22e7cf62239833b5a3a06b1,6.6.143,6.12.94,6.18.36,7.0.13,75e33deda658c1ab3a9336cbdb1436536f9b3660,0,6.7.0,6.13.0,6.19.0
Fix Available
892f643b141aee3f7aa7c0fc61ddcb55c59f1996,5de0527f782430b1109a447646e32033ad018a6a,c8279ae8df68cce9cd3b785e85f7a86c80a46e78,0e753899627b5e28a9fea8bca98262a6f65a2452,6.6.158,6.12.111,6.18.51,7.1,7.2.5,6.12.111-1~deb12u1,6.12.111-1

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading