CVE-2026-31477 Details
Description
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix memory leaks and NULL deref in smb2_lock() smb2_lock() has three error handling issues after list_del() detaches smb_lock from lock_list at no_check_cl: 1) If vfs_lock_file() returns an unexpected error in the non-UNLOCK path, goto out leaks smb_lock and its flock because the out: handler only iterates lock_list and rollback_list, neither of which contains the detached smb_lock. 2) If vfs_lock_file() returns -ENOENT in the UNLOCK path, goto out leaks smb_lock and flock for the same reason. The error code returned to the dispatcher is also stale. 3) In the rollback path, smb_flock_init() can return NULL on allocation failure. The result is dereferenced unconditionally, causing a kernel NULL pointer dereference. Add a NULL check to prevent the crash and clean up the bookkeeping; the VFS lock itself cannot be rolled back without the allocation and will be released at file or connection teardown. Fix cases 1 and 2 by hoisting the locks_free_lock()/kfree() to before the if(!rc) check in the UNLOCK branch so all exit paths share one free site, and by freeing smb_lock and flock before goto out in the non-UNLOCK branch. Propagate the correct error code in both cases. Fix case 3 by wrapping the VFS unlock in an if(rlock) guard and adding a NULL check for locks_free_lock(rlock) in the shared cleanup. Found via call-graph analysis using sqry.
A vulnerability in the Linux kernel's ksmbd component has been addressed, specifically within the smb2_lock() function. This vulnerability involves memory leaks and a NULL pointer dereference caused by improper error handling after the smb_lock is detached from the lock_list. Three main issues were identified: First, an unexpected error from vfs_lock_file() in the non-UNLOCK path can lead to a memory leak of smb_lock and its flock, as the error handling only addresses locks still attached to the lock_list. Second, if vfs_lock_file() returns -ENOENT while attempting to UNLOCK, it also causes a leak for the same reason, in addition to returning a stale error code. Third, during the rollback process, smb_flock_init() may fail to allocate memory, resulting in a NULL pointer dereference. The vulnerability has been fixed by adding appropriate NULL checks, adjusting the error handling to properly free resources, and ensuring that the VFS lock can be correctly rolled back when necessary.
Users can upgrade to the latest version of the Linux kernel where this vulnerability has been fixed. Instructions for downloading the patched version can be found in the Linux kernel documentation.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/309b44ed684496ed3f9c5715d10b899338623512 | kernel.org | Patch |
| https://git.kernel.org/stable/c/3cdacd11b41569ce75b3162142240f2355e04900 | kernel.org | Patch |
| https://git.kernel.org/stable/c/91aeaa7256006d79a37298f5a1df23325db91599 | kernel.org | Patch |
| https://git.kernel.org/stable/c/aab42f0795620cf0d3955a520f571f697d0f9a2a | kernel.org | Patch |
| https://git.kernel.org/stable/c/c9b95ef6f5039f19e46c3a521a4fe1752d91dfe9 | kernel.org | Patch |
| https://git.kernel.org/stable/c/cdac6f7e7e428dc70e3b5898ac6999a72ed13993 | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-476 | NULL Pointer Dereference | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 5.15.1, < 6.1.168 >= 6.2, < 6.6.131 >= 6.7, < 6.12.80 >= 6.13, < 6.18.21 >= 6.19, < 6.19.11 5.15 - 7.0 rc1 7.0 rc2 7.0 rc3 7.0 rc4 7.0 rc5 7.0 rc6 7.0 rc7 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | kernel.org |
| Apr 27, 2026 | Initial Analysis | [email protected] |
| Apr 27, 2026 | CVE Modified | kernel.org |
| Apr 22, 2026 | New CVE Received | kernel.org |