PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-72381 Linux CVE debrief

A use-after-free vulnerability was found in the Linux kernel's ksmbd module. The vulnerability occurs when two concurrent SMB2 durable reconnects race against the kfree() in ksmbd_reopen_durable_fd()'s reopen-success path, leading to a potential use-after-free of fp->owner.name in ksmbd_vfs_compare_durable_owner(). This issue arises from the lack of proper synchronization between the compare-read operation in ksmbd_vfs_compare_durable_owner() and the kfree() operation in ksmbd_reopen_durable_fd(). The vulnerability can lead to a denial-of-service (DoS) or potentially allow an attacker to execute arbitrary code. Linux kernel developers and maintainers should be aware of this issue and take steps to address it.

Vendor
Linux
Product
Unknown
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-15
Original CVE updated
2026-08-15
Advisory published
2026-08-15
Advisory updated
2026-08-15

Who should care

Linux kernel developers and maintainers, Linux distribution vendors, users of Linux systems with ksmbd enabled, and security teams responsible for monitoring and patching Linux systems should be aware of this vulnerability and take steps to address it. Affected systems may be vulnerable to denial-of-service (DoS) or code execution attacks if not properly patched. Linux distribution vendors should prioritize patching and updating their kernels to prevent exploitation of this vulnerability. Users of Linux systems with ksmbd enabled should ensure that their systems are patched and up-to-date to prevent potential attacks. Security teams should monitor system logs for potential exploitation attempts and review system configurations to ensure that ksmbd is properly secured. IT teams responsible for maintaining Linux systems should review and update their patch management processes to ensure timely application of security patches. Additionally, asset owners and operators using Linux systems with ksmbd enabled should verify that their systems are patched and take steps to detect potential exploitation attempts. Vulnerability management teams should prioritize this vulnerability and ensure that affected systems are patched or mitigated. Compensating controls, such as monitoring and detection, should be implemented for exposed systems while remediation is scheduled and verified. IT security teams should also review and update their incident response plans to address potential exploitation of this vulnerability. System administrators responsible for Linux systems should review system configurations and ensure that ksmbd is properly secured and monitored. Network security teams should monitor network traffic for potential exploitation attempts and implement additional security controls as needed. Linux kernel developers and maintainers should review the patch and ensure that it is properly integrated into their kernels. Linux distribution vendors should prioritize patching and updating their kernels to prevent exploitation of this vulnerability. Users of Linux systems with ksmbd enabled should ensure that their systems are patched and up-to-date to prevent potential attacks

Technical summary

The vulnerability occurs in the Linux kernel's ksmbd module, specifically in the ksmbd_vfs_compare_durable_owner() function. Two concurrent SMB2 durable reconnects can race against the kfree() in ksmbd_reopen_durable_fd()'s reopen-success path, leading to a potential use-after-free of fp->owner.name. This issue can be mitigated by applying the patch from the Linux kernel stable repository. The patch serializes access to fp->owner.name, preventing the use-after-free vulnerability.

Defensive priority

Medium

Recommended defensive actions

  • Apply the patch from the Linux kernel stable repository
  • Review and update Linux kernel configurations to ensure ksmbd is properly secured
  • Monitor for potential exploitation attempts
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The vulnerability was resolved by serializing both sides of the race with fp->f_lock. The global durable file-table lock still protects the durable reconnect claim, but fp->owner.name is per-open state and does not need to block unrelated durable table lookups or reconnects. Evidence is limited to the supplied source corpus and may not reflect all affected systems or potential attack vectors. Defenders should verify the patch has been applied and review system logs for potential exploitation attempts.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-72381 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-72381

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-72381 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-72381

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/38637163501fd9e2f684b8cd275d0db5d79f37c6

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/5a5ac2852cd326529d02f778bc1aa6184701f4d7

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/93d4d46bf9d442a12ea87278049ec416962c627f

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/ed98719be41389d416953b8ef9f07a07dfea6b2b

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/fb978d72052704c6b06c6b0f129fcd60b77169f5

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.