PatchSiren cyber security CVE debrief
CVE-2026-72381 Linux CVE debrief
A use-after-free vulnerability was found in the Linux kernel's ksmbd module. The vulnerability occurs when two concurrent SMB2 durable reconnects race against the kfree() in ksmbd_reopen_durable_fd()'s reopen-success path, leading to a potential use-after-free of fp->owner.name in ksmbd_vfs_compare_durable_owner(). This issue arises from the lack of proper synchronization between the compare-read operation in ksmbd_vfs_compare_durable_owner() and the kfree() operation in ksmbd_reopen_durable_fd(). The vulnerability can lead to a denial-of-service (DoS) or potentially allow an attacker to execute arbitrary code. Linux kernel developers and maintainers should be aware of this issue and take steps to address it.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-15
- Original CVE updated
- 2026-08-15
- Advisory published
- 2026-08-15
- Advisory updated
- 2026-08-15
Who should care
Linux kernel developers and maintainers, Linux distribution vendors, users of Linux systems with ksmbd enabled, and security teams responsible for monitoring and patching Linux systems should be aware of this vulnerability and take steps to address it. Affected systems may be vulnerable to denial-of-service (DoS) or code execution attacks if not properly patched. Linux distribution vendors should prioritize patching and updating their kernels to prevent exploitation of this vulnerability. Users of Linux systems with ksmbd enabled should ensure that their systems are patched and up-to-date to prevent potential attacks. Security teams should monitor system logs for potential exploitation attempts and review system configurations to ensure that ksmbd is properly secured. IT teams responsible for maintaining Linux systems should review and update their patch management processes to ensure timely application of security patches. Additionally, asset owners and operators using Linux systems with ksmbd enabled should verify that their systems are patched and take steps to detect potential exploitation attempts. Vulnerability management teams should prioritize this vulnerability and ensure that affected systems are patched or mitigated. Compensating controls, such as monitoring and detection, should be implemented for exposed systems while remediation is scheduled and verified. IT security teams should also review and update their incident response plans to address potential exploitation of this vulnerability. System administrators responsible for Linux systems should review system configurations and ensure that ksmbd is properly secured and monitored. Network security teams should monitor network traffic for potential exploitation attempts and implement additional security controls as needed. Linux kernel developers and maintainers should review the patch and ensure that it is properly integrated into their kernels. Linux distribution vendors should prioritize patching and updating their kernels to prevent exploitation of this vulnerability. Users of Linux systems with ksmbd enabled should ensure that their systems are patched and up-to-date to prevent potential attacks
Technical summary
The vulnerability occurs in the Linux kernel's ksmbd module, specifically in the ksmbd_vfs_compare_durable_owner() function. Two concurrent SMB2 durable reconnects can race against the kfree() in ksmbd_reopen_durable_fd()'s reopen-success path, leading to a potential use-after-free of fp->owner.name. This issue can be mitigated by applying the patch from the Linux kernel stable repository. The patch serializes access to fp->owner.name, preventing the use-after-free vulnerability.
Defensive priority
Medium
Recommended defensive actions
- Apply the patch from the Linux kernel stable repository
- Review and update Linux kernel configurations to ensure ksmbd is properly secured
- Monitor for potential exploitation attempts
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The vulnerability was resolved by serializing both sides of the race with fp->f_lock. The global durable file-table lock still protects the durable reconnect claim, but fp->owner.name is per-open state and does not need to block unrelated durable table lookups or reconnects. Evidence is limited to the supplied source corpus and may not reflect all affected systems or potential attack vectors. Defenders should verify the patch has been applied and review system logs for potential exploitation attempts.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-72381 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-72381
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-72381 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-72381
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/38637163501fd9e2f684b8cd275d0db5d79f37c6
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/5a5ac2852cd326529d02f778bc1aa6184701f4d7
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/93d4d46bf9d442a12ea87278049ec416962c627f
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/ed98719be41389d416953b8ef9f07a07dfea6b2b
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/fb978d72052704c6b06c6b0f129fcd60b77169f5
416baaa9-dc9f-4396-8d5f-8c081fb06d67
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.