Race Condition Vulnerability in Linux Kernel's ksmbd Component
CVE-2026-64142

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
19 July 2026

What is CVE-2026-64142?

A critical race condition vulnerability exists in the ksmbd component of the Linux kernel, specifically within the durable scavenger function. This flaw can lead to list corruption and use-after-free (UAF) errors, which occur due to improper management of file pointer nodes during simultaneous access by multiple handlers. As a result, the system may mistakenly allow access to expired file handles that should have been cleared, potentially leading to system instability and security concerns. The vulnerability stems from the mishandling of reference counts and the reuse of linked list nodes during the scavenging process, necessitating an urgent update to eliminate these risks.

Affected Version(s)

Linux 7f0cb478703cbeaddfe5c9101c5c73cd975d1073 < 3a436932eb397e909d0607d76a8325abd9d85a35

Linux d484d621d40f4a8b8959008802d79bef3609641b < 95f072ef934ca00711d510676b8792cbf59a5aae

Linux d484d621d40f4a8b8959008802d79bef3609641b < 5da69a65b282d2276de22e5194ba0f88c836170c

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.