PatchSiren cyber security CVE debrief
CVE-2026-64396 Linux CVE debrief
A use-after-free vulnerability exists in the Linux kernel's ksmbd module, specifically in the SMB2_LOCK deferred-lock cancellation. This issue can lead to a slab-use-after-free inside __wake_up_common. The vulnerability has been resolved through a series of patches that restructure the cleanup logic after the worker returns from ksmbd_vfs_posix_lock_wait(). This fix ensures that the async work is completely dequeued and serialized under conn->request_lock before locks_free_lock(flock) is called.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-25
- Original CVE updated
- 2026-09-04
- Advisory published
- 2026-07-25
- Advisory updated
- 2026-09-04
Who should care
Linux kernel developers and maintainers, Linux distribution vendors, and users of Linux-based systems should verify and apply patches, monitor system logs, and update kernel versions to prevent potential exploitation of this use-after-free vulnerability in the Linux kernel's ksmbd module.
Why it matters
A use-after-free vulnerability in the Linux kernel's ksmbd module requires patching to prevent potential exploitation. Linux kernel developers, maintainers, and users should verify and apply patches, monitor system logs, and update kernel versions.
- Verify and apply patches to prevent potential use-after-free exploitation
- Monitor system logs for potential exploitation attempts
- Update Linux kernel versions to patched versions
Technical summary
The vulnerability exists in the Linux kernel's ksmbd module, specifically in the SMB2_LOCK deferred-lock cancellation. A use-after-free issue can occur when a blocking byte-range lock request is deferred in the FILE_LOCK_DEFERRED path. The fix involves restructuring the cleanup logic after the worker returns from ksmbd_vfs_posix_lock_wait() to prevent the use-after-free issue. This includes moving list_del(&smb_lock->llist) and release_async_work(work) to the top of the cleanup block, ensuring that the async work is completely dequeued and serialized under conn->request_lock before locks_free_lock(flock) is called.
Defensive priority
High
Recommended defensive actions
- Review and apply the provided patches to the Linux kernel
- Ensure that the Linux kernel version is updated to a patched version
- Monitor system logs for potential exploitation attempts
- Verify affected product deployments exist in managed environments and assign an owner for follow-up
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The vulnerability was introduced in the Linux kernel and affects various versions. The issue arises when a blocking byte-range lock request is deferred in the FILE_LOCK_DEFERRED path. The fix involves restructuring the cleanup logic after the worker returns from ksmbd_vfs_posix_lock_wait().
Sources and references
Verified primary and authoritative sources
-
CVE-2026-64396 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-64396
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-64396 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-64396
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/367c42a611fe488b7b03f1f6737f4dee0e8b20a2
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/463bbd79698513af4dad50fe1c573825f297ca2e
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/5aa1cb01155f96824003baf7997cdf1f150caba3
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/5c75275c0fc9a2deb0d8f5604edcb16f288171c8
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/7703fd9aba1f2483c8e55f9ff73b7663e0761ed9
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/d20d1c8ba5765d1d12eefc0aee6385ab3f240e1e
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.