CVE 9.8 CRITICAL

smb: server: fix use-after-free in smb2_open()_CVE-2026-43378

9.8 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

In the Linux kernel, the following vulnerability has been resolved:

smb: server: fix use-after-free in smb2_open()

The opinfo pointer obtained via rcu_dereference(fp->f_opinfo) is
dereferenced after rcu_read_unlock(), creating a use-after-free
window.

AI Analysis

Use-after-free vulnerability in the Linux kernel

Basic Information

ID CVE-2026-43378
Source Linux
Published May 8, 2026 at 14:21
Modified May 20, 2026 at 16:08

Affected Product

Vendor Linux
Product Linux
Version e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9
Affected Versions Linux Linux e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9
Linux Linux e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9
Linux Linux e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9
Linux Linux e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9
Linux Linux e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9
Linux Linux e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9
Linux Linux 5.15

AI Assessment

AI Score 9.8 / 10
AI Severity Critical
Vendor Linux Foundation
Product Linux Kernel
Version 5.15

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.