Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

CVE-2026-89635

ksmbd: only rebind the reopened file's own oplock on durable reconnect
Back to all
CVE

CVE-2026-89635

ksmbd: only rebind the reopened file's own oplock on durable reconnect

In the Linux kernel, the following vulnerability has been resolved:

ksmbd: only rebind the reopened file's own oplock on durable reconnect

ksmbdreopendurablefd() walks the inode's mop_list and rebinds every

detached oplock to the reconnecting session:

listforeachentryrcu(op, &ci->moplist, op_entry,

lockdepisheld(&ci->m_lock)) {

if (op->conn)

continue;

op->conn = ksmbdconnget(fp->conn);

op->sess = work->sess;

}

The only key is op->conn == NULL, which every detached durable handle on

that inode matches, not just the one owned by fp.  When two sessions hold

durable handles on the same file and both disconnect, reconnecting one of

them adopts the other session's oplock: op->sess is overwritten with the

reconnecting session without taking a reference on it, while op->conn

pins the connection.

The sibling teardown path, sessionfdcheck(), keys on the identity of

the connection being torn down (op->conn == conn) rather than on shared

state, and so does not have this problem.

Once the adopting session is destroyed, ksmbdsessiondestroy() frees it

while the foreign oplock still points at it.  The reader in

ksmbdclosefdappinstance_id() validates only opinfo->conn, which is

still live thanks to the reference taken above, and then dereferences the

stale session:

if (!opinfo->conn) {

upread(&fp->fci->m_lock);

goto out;

}

ft = &opinfo->sess->file_table;

write_lock(&ft->lock);

  BUG: KASAN: slab-use-after-free in rawwrite_lock+0x74/0xd0

  Write of size 4 at addr ffff88810a970528 by task kworker/0:0/9

  Workqueue: ksmbd-io handleksmbdwork

  Call Trace:

   rawwrite_lock+0x74/0xd0

   ksmbdclosefdappinstance_id+0x183/0x410

   smb2_open+0x1346/0x4430

   handleksmbdwork+0x2bb/0x7b0

Reached from an authenticated session against a share with the default

durable-handle and oplock configuration: two sessions open the same file

with a durable-v2 handle and an RH lease under distinct AppInstanceIds,

both log off, one reconnects with DH2C, and a later durable-v2 create

carrying the other AppInstanceId walks into the freed session.

Constrain the loop to the oplock owned by the file being reopened.

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
9.8
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
0
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
-

Related Resources

No items found.

References

https://git.kernel.org/stable/c/3f220a0a62e6b9b391c9d1f0e6580b05173cc7f7, https://git.kernel.org/stable/c/74e3ef4630f004c0de40c0540648a5a4033c6c9d, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89635.json, https://nvd.nist.gov/vuln/detail/CVE-2026-89635, https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Severity

9.8

CVSS Score
0
10

Basic Information

Base CVSS
9.8
EPSS Probability
0.00553%
EPSS Percentile
0.44464%
Introduced Version
f363a0fb134a3eb9e47368b1edbd251fd76be84b,7.2.0,0
Fix Available
3f220a0a62e6b9b391c9d1f0e6580b05173cc7f7,7.2.4

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading