Race Condition Vulnerability in Linux Kernel's ksmbd Component
CVE-2026-64142
What is CVE-2026-64142?
A critical race condition vulnerability exists in the ksmbd component of the Linux kernel, specifically within the durable scavenger function. This flaw can lead to list corruption and use-after-free (UAF) errors, which occur due to improper management of file pointer nodes during simultaneous access by multiple handlers. As a result, the system may mistakenly allow access to expired file handles that should have been cleared, potentially leading to system instability and security concerns. The vulnerability stems from the mishandling of reference counts and the reuse of linked list nodes during the scavenging process, necessitating an urgent update to eliminate these risks.
Affected Version(s)
Linux 7f0cb478703cbeaddfe5c9101c5c73cd975d1073 < 3a436932eb397e909d0607d76a8325abd9d85a35
Linux d484d621d40f4a8b8959008802d79bef3609641b < 95f072ef934ca00711d510676b8792cbf59a5aae
Linux d484d621d40f4a8b8959008802d79bef3609641b < 5da69a65b282d2276de22e5194ba0f88c836170c