9.8
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Description
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: fix use-after-free in smb_lazy_parent_lease_break_close()
opinfo pointer obtained via rcu_dereference(fp->f_opinfo) is being
accessed after rcu_read_unlock() has been called. This creates a
race condition where the memory could be freed by a concurrent
writer between the unlock and the subsequent pointer dereferences
(opinfo->is_lease, etc.), leading to a use-after-free.
ksmbd: fix use-after-free in smb_lazy_parent_lease_break_close()
opinfo pointer obtained via rcu_dereference(fp->f_opinfo) is being
accessed after rcu_read_unlock() has been called. This creates a
race condition where the memory could be freed by a concurrent
writer between the unlock and the subsequent pointer dereferences
(opinfo->is_lease, etc.), leading to a use-after-free.
Basic Information
ID
CVE-2026-43379
Source
Linux
Published
May 8, 2026 at 14:21
Modified
May 11, 2026 at 06:33
Affected Product
Vendor
Linux
Product
Linux
Version
27b40b7bfcd121fe13a150ffe11957630cf49246
Affected Versions
Linux Linux 27b40b7bfcd121fe13a150ffe11957630cf49246
Linux Linux 5fb282ba4fef8985a5acf2b32681f2ec07732561
Linux Linux 5fb282ba4fef8985a5acf2b32681f2ec07732561
Linux Linux 5fb282ba4fef8985a5acf2b32681f2ec07732561
Linux Linux 5fb282ba4fef8985a5acf2b32681f2ec07732561
Linux Linux 6.9
Linux Linux 5fb282ba4fef8985a5acf2b32681f2ec07732561
Linux Linux 5fb282ba4fef8985a5acf2b32681f2ec07732561
Linux Linux 5fb282ba4fef8985a5acf2b32681f2ec07732561
Linux Linux 5fb282ba4fef8985a5acf2b32681f2ec07732561
Linux Linux 6.9
References
- git.kernel.org /stable/c/bf4d66d72e4a9e268c1012c331ce9eaedb5e2086
- git.kernel.org /stable/c/960699317d39f46611f4ebeb69edc567c1f4e6b6
- git.kernel.org /stable/c/dbbd328cf58261ca239756fe1c0d10c9518d3399
- git.kernel.org /stable/c/b3568347c51c46e2cabc356bc34676df98296619
- git.kernel.org /stable/c/eac3361e3d5dd8067b3258c69615888eb45e9f25