From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 49B544BFE90 for ; Fri, 11 Sep 2026 19:59:50 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789156799; cv=none; b=mbTVtSTOeoOzLxnvw2LCJh6U8iPcmp08/vmYfX9jtnuq4jD5ZZYk5gDrM1gpYTORVqPCMOedsY/zGjEzDVWlkMqqu+8dfLda4WZn5Xz8LxyQtz1Fv6dzHFb//JD3scjTlK5NTXIXuIhIIEfwgMIbT468pIaa2Pt7lUfx+WzkI1U= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789156799; c=relaxed/simple; bh=NG4Gl5YMqsCDKceAV2pUvtKlAT7LsD2Agc1Drfqzke0=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=V96O8qR6L/VEtpV3NvGVK5WAuj512rb/JhjG+IcoEMzkDKwUMABPW3qVxyz0GMJEWS4Lx7fEEAgMLpC7Yfpf6AenoEqn6GdrpTlFZkTSKSwkDCPgnyIcFYAoll/CBs/ccTzPpKrmTikxIvyVzao95fOSlKn9cRkOA3nX6SuFpx4= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=SmLDxLst; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="SmLDxLst" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 6BD851F000FF; Fri, 11 Sep 2026 19:59:49 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1789156790; bh=L6RFId4xgDkahs9OXjnH3kR+7buh5FDtsvTViSQEzLo=; h=From:To:Cc:Subject:Date:Reply-To; b=SmLDxLstaVcOyNT4yMKfzPpsyTb1QOh/VhvSK0NBdHdjwrypMWleyXdHYV4RqEe7p Fzn7IR9lPQKJcPnOm8svV8iB0Jcur+x4W4XG14PGoFABdD5pb6Z/52roKLu0LFBCIS /rO8ByfjO/5pPVeALzPC292nKOpM6zxfC24VR018= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-89635: ksmbd: only rebind the reopened file's own oplock on durable reconnect Date: Fri, 11 Sep 2026 21:45:24 +0200 Message-ID: <2026091140-CVE-2026-89635-98cc@gregkh> X-Mailer: git-send-email 2.55.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=3862; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=qiR6w0+MBnSJz+d9c8w6lIR+Slpr3qZ94Y60aj7MonA=; b=owGbwMvMwCRo6H6F97bub03G02pJDFlLIkskTq/1XbmaI4DxHAtL39s5NXbyR4umWH7iLlv3Y YGRtVViRywLgyATg6yYIsuXbTxH91ccUvQytD0NM4eVCWQIAxenAEzkZAvD/MCq3KiyFhcntrkP xUuWrPQtuOMewbCgf0HQ7IVx/vfvbPULVV371X8fV3wRAA== X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: ksmbd: only rebind the reopened file's own oplock on durable reconnect ksmbd_reopen_durable_fd() walks the inode's m_op_list and rebinds every detached oplock to the reconnecting session: list_for_each_entry_rcu(op, &ci->m_op_list, op_entry, lockdep_is_held(&ci->m_lock)) { if (op->conn) continue; op->conn = ksmbd_conn_get(fp->conn); op->sess = work->sess; } The only key is op->conn == NULL, which every detached durable handle on that inode matches, not just the one owned by fp. When two sessions hold durable handles on the same file and both disconnect, reconnecting one of them adopts the other session's oplock: op->sess is overwritten with the reconnecting session without taking a reference on it, while op->conn pins the connection. The sibling teardown path, session_fd_check(), keys on the identity of the connection being torn down (op->conn == conn) rather than on shared state, and so does not have this problem. Once the adopting session is destroyed, ksmbd_session_destroy() frees it while the foreign oplock still points at it. The reader in ksmbd_close_fd_app_instance_id() validates only opinfo->conn, which is still live thanks to the reference taken above, and then dereferences the stale session: if (!opinfo->conn) { up_read(&fp->f_ci->m_lock); goto out; } ft = &opinfo->sess->file_table; write_lock(&ft->lock); BUG: KASAN: slab-use-after-free in _raw_write_lock+0x74/0xd0 Write of size 4 at addr ffff88810a970528 by task kworker/0:0/9 Workqueue: ksmbd-io handle_ksmbd_work Call Trace: _raw_write_lock+0x74/0xd0 ksmbd_close_fd_app_instance_id+0x183/0x410 smb2_open+0x1346/0x4430 handle_ksmbd_work+0x2bb/0x7b0 Reached from an authenticated session against a share with the default durable-handle and oplock configuration: two sessions open the same file with a durable-v2 handle and an RH lease under distinct AppInstanceIds, both log off, one reconnects with DH2C, and a later durable-v2 create carrying the other AppInstanceId walks into the freed session. Constrain the loop to the oplock owned by the file being reopened. The Linux kernel CVE team has assigned CVE-2026-89635 to this issue. Affected and fixed versions =========================== Issue introduced in 7.2 with commit f363a0fb134a3eb9e47368b1edbd251fd76be84b and fixed in 7.2.4 with commit 74e3ef4630f004c0de40c0540648a5a4033c6c9d Issue introduced in 7.2 with commit f363a0fb134a3eb9e47368b1edbd251fd76be84b and fixed in 7.3-rc1 with commit 3f220a0a62e6b9b391c9d1f0e6580b05173cc7f7 Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-89635 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: fs/smb/server/vfs_cache.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/74e3ef4630f004c0de40c0540648a5a4033c6c9d https://git.kernel.org/stable/c/3f220a0a62e6b9b391c9d1f0e6580b05173cc7f7