U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2026-64437

Change History

New CVE Received from kernel.org 7/25/2026 6:17:28 AM

Action Type Old Value New Value
Added Description

                  
                
              
In the Linux kernel, the following vulnerability has been resolved:

ksmbd: fix use-after-free of a deferred file_lock on SMB2_CLOSE then SMB2_CANCEL

Commit f580d27e8928 ("ksmbd: fix use-after-free of a deferred file_lock on
double SMB2_CANCEL") made smb2_cancel() skip a work whose state is
KSMBD_WORK_CANCELLED, so its cancel_fn cannot be fired a second time. But
KSMBD_WORK has three states (ACTIVE, CANCELLED, CLOSED), and the same
freeing producer path is reached for CLOSED too:

  SMB2_CLOSE on the locking handle -> set_close_state_blocked_works() sets
  the deferred work's state to KSMBD_WORK_CLOSED and wakes the smb2_lock()
  worker. The worker takes the non-ACTIVE early-exit, locks_free_lock()s
  the file_lock and, because the state is not KSMBD_WORK_CANCELLED, takes
  the STATUS_RANGE_NOT_LOCKED branch with "goto out2" -- which, like the
  cancelled branch, skips release_async_work(). The work stays on
  conn->async_requests with a live cancel_fn = smb2_remove_blocked_lock
  pointing at the freed file_lock.

A subsequent SMB2_CANCEL for the same AsyncId then passes the
KSMBD_WORK_CANCELLED-only guard (its state is KSMBD_WORK_CLOSED), so
smb2_cancel() fires cancel_fn again over the freed file_lock -- the same
use-after-free fixed, via SMB2_CLOSE instead of a first SMB2_CANCEL:

  BUG: KASAN: slab-use-after-free in __locks_delete_block
    __locks_delete_block
    locks_delete_block
    ksmbd_vfs_posix_lock_unblock
    smb2_remove_blocked_lock
    smb2_cancel                 <- 2nd SMB2_CANCEL fires cancel_fn
    handle_ksmbd_work
  Allocated by ...: locks_alloc_lock <- smb2_lock
  Freed by ...:     locks_free_lock  <- smb2_lock (non-ACTIVE early-exit)
  ... cache file_lock_cache of size 192

Reproduced on mainline 7.1-rc7 (which already contains f580d27e8928) with
KASAN by an authenticated SMB client; the double-SMB2_CANCEL control is
silent on that kernel, so the splat is attributable to the CLOSE trigger.

Only an ACTIVE deferred work may have its cancel_fn fired: both terminal
states (CANCELLED and CLOSED) reach the smb2_lock() early-exit that frees
the file_lock and skips release_async_work(). Guard on KSMBD_WORK_ACTIVE
so any non-active work is skipped.
Added Reference

                  
                
              
https://git.kernel.org/stable/c/10f293a07f9e10e988b0ae44e2e99c631f5a68e0
Added Reference

                  
                
              
https://git.kernel.org/stable/c/12c36c99655f325befe50c26842f7deca414c381
Added Reference

                  
                
              
https://git.kernel.org/stable/c/94083db751930b1540ddff2b54d4677549c57f81
Added Reference

                  
                
              
https://git.kernel.org/stable/c/a796ba4e61d5e14e07b79a359faac69f8f9b22a3
Added Reference

                  
                
              
https://git.kernel.org/stable/c/b8e274e69ab09222c7a552c7c0c1eef9ce627fc1
Added Reference

                  
                
              
https://git.kernel.org/stable/c/ddb9239828336b36d8a3ef5943fdffb2f55b6508
Added Affected

                  
                
              
[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/smb/server/smb2pdu.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"b7063c7426ea5a4d15e01b60538718765392f49d","lessThan":"a796ba4e61d5e14e07b79a359faac69f8f9b22a3","versionType":"git","status":"affected"},{"version":"0da2e073f9cbf4985a0fd9acb71bc5ff599f8afd","lessThan":"b8e274e69ab09222c7a552c7c0c1eef9ce627fc1","versionType":"git","status":"affected"},{"version":"89ae9df09d2c1fb4a4eb495c113a7ce1dca34147","lessThan":"ddb9239828336b36d8a3ef5943fdffb2f55b6508","versionType":"git","status":"affected"},{"version":"14d2eee0193ac3cd1bf3d014373449f0b8d35d6d","lessThan":"94083db751930b1540ddff2b54d4677549c57f81","versionType":"git","status":"affected"},{"version":"f580d27e8928828693df44ba2db0fffdbe11dfea","lessThan":"12c36c99655f325befe50c26842f7deca414c381","versionType":"git","status":"affected"},{"version":"f580d27e8928828693df44ba2db0fffdbe11dfea","lessThan":"10f293a07f9e10e988b0ae44e2e99c631f5a68e0","versionType":"git","status":"affected"},{"version":"2b2eda2821cff1d1b5a423b6ee7d8fc6fbc8e694","versionType":"git","status":"affected"},{"version":"6.1.176","lessThan":"6.1.178","versionType":"semver","status":"affected"},{"version":"6.6.143","lessThan":"6.6.145","versionType":"semver","status":"affected"},{"version":"6.12.94","lessThan":"6.12.96","versionType":"semver","status":"affected"},{"version":"6.18.36","lessThan":"6.18.39","versionType":"semver","status":"affected"},{"version":"7.0.13","lessThan":"7.1","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/smb/server/smb2pdu.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.1","status":"affected"},{"version":"0","lessThan":"7.1","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]