Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

DEBIAN-CVE-2026-72381

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free of fp->owner.name in durable handle owner check Two concurrent SMB2 durable reconnects (DH2C/DHnC) on th...
Back to all
CVE

DEBIAN-CVE-2026-72381

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free of fp->owner.name in durable handle owner check Two concurrent SMB2 durable reconnects (DH2C/DHnC) on th...

In the Linux kernel, the following vulnerability has been resolved:  ksmbd: fix use-after-free of fp->owner.name in durable handle owner check  Two concurrent SMB2 durable reconnects (DH2C/DHnC) on the same persistentid race the fp->owner.name compare-read in ksmbdvfscomparedurableowner() against the kfree() in ksmbdreopendurablefd()'s reopen-success path. fp->owner.name is a standalone kstrdup() buffer whose lifetime is independent of the fp refcount, and the two sites share no lock: the compare reads the buffer while the reopen frees it, so the strcmp() can dereference freed memory.  Commit 7ce4fc40018d ("ksmbd: fix durable reconnect double-bind race in ksmbdreopendurablefd") made the fp->conn claim atomic under globalft.lock (closing the owner.name double-free and the ksmbdfile write-UAF), but the compare-read versus reopen-free pair was left unserialized.    BUG: KASAN: slab-use-after-free in strcmp+0x2c/0x80   Read of size 1 by task kworker     strcmp     ksmbdvfscomparedurableowner     smb2checkdurableoplock     smb2open   Freed by task kworker:     kfree     ksmbdreopendurablefd     smb2open   Allocated by task kworker:     kstrdup     sessionfdcheck     smb2sessionlogoff   The buggy address belongs to the cache kmalloc-8  Serialize both sides of the race with fp->flock.  The global durable file-table lock still protects the durable reconnect claim, but fp->owner.name is per-open state and does not need to block unrelated durable table lookups or reconnects.  The teardown is left at its existing location after the reopen-success point so that an _openid() rollback still retains owner.name for a later legitimate reconnect to verify.

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
-
C
H
U
0
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
-

Related Resources

No items found.

References

https://security-tracker.debian.org/tracker/CVE-2026-72381

Severity

9.8

CVSS Score
0
10

Basic Information

Base CVSS
9.8
EPSS Probability
0%
EPSS Percentile
0%
Introduced Version
0
Fix Available
6.12.100-1,7.1.5-1

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading