CVE-2026-31444 Details
Description
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free and NULL deref in smb_grant_oplock() smb_grant_oplock() has two issues in the oplock publication sequence: 1) opinfo is linked into ci->m_op_list (via opinfo_add) before add_lease_global_list() is called. If add_lease_global_list() fails (kmalloc returns NULL), the error path frees the opinfo via __free_opinfo() while it is still linked in ci->m_op_list. Concurrent m_op_list readers (opinfo_get_list, or direct iteration in smb_break_all_levII_oplock) dereference the freed node. 2) opinfo->o_fp is assigned after add_lease_global_list() publishes the opinfo on the global lease list. A concurrent find_same_lease_key() can walk the lease list and dereference opinfo->o_fp->f_ci while o_fp is still NULL. Fix by restructuring the publication sequence to eliminate post-publish failure: - Set opinfo->o_fp before any list publication (fixes NULL deref). - Preallocate lease_table via alloc_lease_table() before opinfo_add() so add_lease_global_list() becomes infallible after publication. - Keep the original m_op_list publication order (opinfo_add before lease list) so concurrent opens via same_client_has_lease() and opinfo_get_list() still see the in-flight grant. - Use opinfo_put() instead of __free_opinfo() on err_out so that the RCU-deferred free path is used. This also requires splitting add_lease_global_list() to take a preallocated lease_table and changing its return type from int to void, since it can no longer fail.
A use-after-free and null dereference vulnerability has been identified in the Linux kernel's ksmbd component, specifically within the smb_grant_oplock() function. This vulnerability arises from two main issues in the oplock publication sequence. First, the oplock information is linked to the client's operation list before the global lease list is updated. If the lease update fails, the oplock information is freed while still being referenced, leading to a use-after-free condition. Second, the oplock information's file pointer is set after it has been published on the global lease list, allowing a concurrent operation to dereference a null pointer. These issues can be exploited by concurrent readers of the operation list or the lease list, causing them to access freed memory or null pointers.
Users can upgrade to the latest stable version of the Linux kernel, where this vulnerability has been addressed. Instructions for downloading the latest version can be found on the official Linux kernel website.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/48623ec358c1c600fa1e38368746f933e0f1a617 | kernel.org | Patch |
| https://git.kernel.org/stable/c/6d7e5a918c1d0aad06db0e17677b66fc9a471021 | kernel.org | Patch |
| https://git.kernel.org/stable/c/7de55bba69cbf0f9280daaea385daf08bc076121 | kernel.org | Patch |
| https://git.kernel.org/stable/c/9e785f004cbc56390479b77375726ea9b0d1a8a6 | kernel.org | Patch |
| https://git.kernel.org/stable/c/a5c6f6d6ceefed2d5210ee420fb75f8362461f46 | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-416 | Use After Free | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 6.12.78, < 6.12.80 >= 6.18.19, < 6.18.21 >= 6.19.9, < 6.19.11 6.6.130 7.0 rc4 7.0 rc5 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | kernel.org |
| May 7, 2026 | Initial Analysis | [email protected] |
| Apr 27, 2026 | CVE Modified | kernel.org |
| Apr 22, 2026 | New CVE Received | kernel.org |