Bug 2517032 (CVE-2026-74522) - CVE-2026-74522 kernel: ksmbd: fix use-after-free in __close_file_table_ids()
Summary: CVE-2026-74522 kernel: ksmbd: fix use-after-free in __close_file_table_ids()
Keywords:
Status: NEW
Alias: CVE-2026-74522
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-08-15 12:46 UTC by OSIDB Bzimport
Modified: 2026-08-19 19:20 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-08-15 12:46:03 UTC
In the Linux kernel, the following vulnerability has been resolved:

ksmbd: fix use-after-free in __close_file_table_ids()

A ksmbd_file can remain alive after logical close while another session
holds a temporary reference obtained through ksmbd_lookup_fd_inode().
ksmbd_close_fd() currently marks the file closed and drops the idr-owned
reference, but leaves the pointer published in the closing session's idr
until the final reference is dropped.

If the foreign holder performs the final ksmbd_fd_put(), __put_fd_final()
supplies the foreign session's file table to __ksmbd_close_fd(). The object
is then freed without being removed from its owner's idr, and the owner
session later dereferences the stale pointer during file-table teardown.

Remove the volatile id from the owner's idr while ksmbd_close_fd() still
holds that table's lock, and clear volatile_id before dropping
the idr-owned reference. A later foreign final put then only performs
physical destruction and cannot remove the object from the wrong table.

Comment 1 Mauro Matteo Cascella 2026-08-19 19:19:06 UTC
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2026081545-CVE-2026-74522-bc43@gregkh/T


Note You need to log in before you can comment on or make changes to this bug.