In the Linux kernel, the following vulnerability has been resolved:
smb: prevent use-after-free due to open_cached_dir error paths
If open_cached_dir() encounters an error parsing the lease from the server, the error handling may race with receiving a lease break, resulting in open_cached_dir() freeing the cfid while the queued work is pending.
Update open_cached_dir() to drop refs rather than directly freeing the cfid.
Have cached_dir_lease_break(), cfids_laundromat_worker(), and invalidate_all_cached_dirs() clear has_lease immediately while still holding cfids->cfid_list_lock, and then use this to also simplify the reference counting in cfids_laundromat_worker() and invalidate_all_cached_dirs().
Fixes this KASAN splat (which manually injects an error and lease break in open_cached_dir()):
================================================================== BUG: KASAN: slab-use-after-free in smb2_cached_lease_break+0x27/0xb0 Read of size 8 at addr ffff88811cc24c10 by task kworker/3:1/65
CPU: 3 UID: 0 PID: 65 Comm: kworker/3:1 Not tainted 6.12.0-rc6-g255cf264e6e5-dirty #87 Hardware name: VMware, Inc. VMware Virtual Platform/440BX Desktop Reference Platform, BIOS 6.00 11/12/2020 Workqueue: cifsiod smb2_cached_lease_break Call Trace: <TASK> dump_stack_lvl+0x77/0xb0 print_report+0xce/0x660 kasan_report+0xd3/0x110 smb2_cached_lease_break+0x27/0xb0 process_one_work+0x50a/0xc50 worker_thread+0x2ba/0x530 kthread+0x17c/0x1c0 ret_from_fork+0x34/0x60 ret_from_fork_asm+0x1a/0x30 </TASK>
Allocated by task 2464: kasan_save_stack+0x33/0x60 kasan_save_track+0x14/0x30 __kasan_kmalloc+0xaa/0xb0 open_cached_dir+0xa7d/0x1fb0 smb2_query_path_info+0x43c/0x6e0 cifs_get_fattr+0x346/0xf10 cifs_get_inode_info+0x157/0x210 cifs_revalidate_dentry_attr+0x2d1/0x460 cifs_getattr+0x173/0x470 vfs_statx_path+0x10f/0x160 vfs_statx+0xe9/0x150 vfs_fstatat+0x5e/0xc0 __do_sys_newfstatat+0x91/0xf0 do_syscall_64+0x95/0x1a0 entry_SYSCALL_64_after_hwframe+0x76/0x7e
Freed by task 2464: kasan_save_stack+0x33/0x60 kasan_save_track+0x14/0x30 kasan_save_free_info+0x3b/0x60 __kasan_slab_free+0x51/0x70 kfree+0x174/0x520 open_cached_dir+0x97f/0x1fb0 smb2_query_path_info+0x43c/0x6e0 cifs_get_fattr+0x346/0xf10 cifs_get_inode_info+0x157/0x210 cifs_revalidate_dentry_attr+0x2d1/0x460 cifs_getattr+0x173/0x470 vfs_statx_path+0x10f/0x160 vfs_statx+0xe9/0x150 vfs_fstatat+0x5e/0xc0 __do_sys_newfstatat+0x91/0xf0 do_syscall_64+0x95/0x1a0 entry_SYSCALL_64_after_hwframe+0x76/0x7e
Last potentially related work creation: kasan_save_stack+0x33/0x60 __kasan_record_aux_stack+0xad/0xc0 insert_work+0x32/0x100 __queue_work+0x5c9/0x870 queue_work_on+0x82/0x90 open_cached_dir+0x1369/0x1fb0 smb2_query_path_info+0x43c/0x6e0 cifs_get_fattr+0x346/0xf10 cifs_get_inode_info+0x157/0x210 cifs_revalidate_dentry_attr+0x2d1/0x460 cifs_getattr+0x173/0x470 vfs_statx_path+0x10f/0x160 vfs_statx+0xe9/0x150 vfs_fstatat+0x5e/0xc0 __do_sys_newfstatat+0x91/0xf0 do_syscall_64+0x95/0x1a0 entry_SYSCALL_64_after_hwframe+0x76/0x7e
The buggy address belongs to the object at ffff88811cc24c00 which belongs to the cache kmalloc-1k of size 1024 The buggy address is located 16 bytes inside of freed 1024-byte region [ffff88811cc24c00, ffff88811cc25000)
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | No solution existsUpgrade linux | May 15, 2025 | Dec 27, 2024 |
| Dell Powerstore Dsa2026115 | — | Upgrade Dell PowerStoreOS to the latest version | Feb 25, 2026 | Feb 24, 2026 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Dec 27, 2024 |
| Ubuntu | — | Upgrade linux-image-generic-lpaeUpgrade linux-image-6.8.0-1028-raspiUpgrade linux-image-generic-64k-hwe-24.04Upgrade linux-image-6.8.0-1026-nvidia-lowlatency-64kUpgrade linux-image-6.11.0-1009-azure-fdeUpgrade linux-image-oracleUpgrade linux-image-oem-24.04Upgrade linux-image-6.8.0-1024-oracle-64kUpgrade linux-image-lowlatency-hwe-22.04Upgrade linux-image-oem-24.04bUpgrade linux-image-gcp-64k-lts-24.04Upgrade linux-image-nvidia-lowlatency-64kUpgrade linux-image-6.8.0-1026-nvidia-lowlatencyUpgrade linux-image-6.11.0-18-generic-64kUpgrade linux-image-6.8.0-2023-raspi-realtimeUpgrade linux-image-oem-22.04dUpgrade linux-image-genericUpgrade linux-image-6.8.0-1028-gcpUpgrade linux-image-lowlatency-64kUpgrade linux-image-generic-64kUpgrade linux-image-6.8.0-1027-azureUpgrade linux-image-6.8.0-58-genericUpgrade linux-image-nvidia-64k-hwe-22.04Upgrade linux-image-azureUpgrade linux-image-gkeopUpgrade linux-image-6.8.0-1024-oracleUpgrade linux-image-nvidia-lowlatencyUpgrade linux-image-gcp-64kUpgrade linux-image-oracle-64k-lts-24.04Upgrade linux-image-generic-64k-hwe-22.04Upgrade linux-image-6.8.0-58-generic-64kUpgrade linux-image-realtimeUpgrade linux-image-6.8.0-1024-ibmUpgrade linux-image-oracle-lts-24.04Upgrade linux-image-raspiUpgrade linux-image-6.11.0-1009-awsUpgrade linux-image-nvidia-64k-6.8Upgrade linux-image-nvidia-hwe-22.04Upgrade linux-image-6.11.0-1008-raspiUpgrade linux-image-nvidiaUpgrade linux-image-gkeUpgrade linux-image-6.8.0-1026-nvidiaUpgrade linux-image-6.8.0-1026-nvidia-64kUpgrade linux-image-nvidia-6.8Upgrade linux-image-oem-22.04Upgrade linux-image-lowlatencyUpgrade linux-image-6.8.0-58-lowlatency-64kUpgrade linux-image-awsUpgrade linux-image-azure-fde-lts-24.04Upgrade linux-image-oem-24.04aUpgrade linux-image-gcpUpgrade linux-image-realtime-hwe-24.04Upgrade linux-image-6.11.0-1011-oracleUpgrade linux-image-6.8.0-1028-gcp-64kUpgrade linux-image-6.11.0-18-genericUpgrade linux-image-virtual-hwe-22.04Upgrade linux-image-oem-22.04cUpgrade linux-image-azure-lts-24.04Upgrade linux-image-6.8.0-1026-oemUpgrade linux-image-gkeop-6.8Upgrade linux-image-generic-hwe-22.04Upgrade linux-image-6.11.0-1009-gcpUpgrade linux-image-azure-fdeUpgrade linux-image-6.8.0-1010-gkeopUpgrade linux-image-azure-nvidiaUpgrade linux-image-kvmUpgrade linux-image-virtual-hwe-24.04Upgrade linux-image-ibm-lts-24.04Upgrade linux-image-nvidia-64kUpgrade linux-image-ibm-classicUpgrade linux-image-gcp-lts-24.04Upgrade linux-image-raspi-realtimeUpgrade linux-image-oem-22.04aUpgrade linux-image-lowlatency-64k-hwe-22.04Upgrade linux-image-6.8.0-58-lowlatencyUpgrade linux-image-6.11.0-1005-realtimeUpgrade linux-image-6.8.0-1027-azure-fdeUpgrade linux-image-virtualUpgrade linux-image-6.11.0-1009-azureUpgrade linux-image-6.11.0-1011-oracle-64kUpgrade linux-image-aws-lts-24.04Upgrade linux-image-generic-hwe-24.04Upgrade linux-image-6.8.0-1023-gkeUpgrade linux-image-6.11.0-1010-lowlatency-64kUpgrade linux-image-6.11.0-1015-oemUpgrade linux-image-6.8.0-1027-awsUpgrade linux-image-oracle-64kUpgrade linux-image-oem-22.04bUpgrade linux-image-6.8.1-1020-realtimeUpgrade linux-image-6.8.0-1014-azure-nvidiaUpgrade linux-image-ibmUpgrade linux-image-6.11.0-1010-lowlatency | Feb 20, 2025 | Dec 27, 2024 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | May 27, 2026 | Dec 27, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub