CVE-2026-80926

Critical

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in oplock break notification smb2_oplock_break_noti() reads opinfo->conn without any lock and dereferences it after two allocations which may sleep. When the durable handle owning the oplock is disconnected, session_fd_check() clears opinfo->conn and drops its conn reference under ci->m_lock, and the last ksmbd_conn_put() frees the connection. A break triggered by another connection that races with the teardown can then resurrect the freed connection: ksmbd_conn_get() is a plain atomic_inc, and the queued break work later dereferences the stale conn via ksmbd_conn_write(), a use-after-free reachable by any authenticated client holding a durable batch oplock. Thread the caller's inode into the notification path instead of taking a new reference on it. Every caller of oplock_break() already holds a live ksmbd_file (or an explicit ksmbd_inode_lookup_lock() reference, in the parent lease break paths) on the inode that owns the break target's oplock list, so ci cannot be freed during the call, and its lock can be taken without dereferencing opinfo->o_fp, which a concurrent close may free. Select and pin the connection under ci->m_lock, the same lock session_fd_check() and ksmbd_reopen_durable_fd() use to update opinfo->conn, so a concurrent detach either loses the race to the clear or keeps the connection alive until the notification work releases it. Transfer the reference to the work item and release it on allocation failures.

Package Linux Kernel
Published 2026-09-11
Last modified 2026-10-03
CVSS version 3.1
Patch available
Yes

CVSS 3.1 score

9.8

out of 10
Critical
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected versions

Linux kernel versions 6.6.143, 6.12.94, 6.18.36, 7.0.13, 7.1 and later are affected. Fixed in 6.6.158, 6.12.111, 6.18.51, 7.2.5, 7.3-rc2 and their respective stable series.

Affected from
≥ 6.6.143 ≥ 6.12.94 ≥ 6.18.36 ≥ 7.0.13 ≥ 7.1
Fixed in
✓ 6.6.158 6.6.x ✓ 6.12.111 6.12.x ✓ 6.18.51 6.18.x ✓ 7.2.5 7.2.x ✓ 7.3-rc2

Frequently asked questions

  • What is CVE-2026-80926?

    CVE-2026-80926 is a Critical severity Linux kernel vulnerability with a CVSS score of 9.8 out of 10 . It affects Linux kernel versions from 6.6.143 onward and has been patched in 6.6.158, 6.12.111, 6.18.51 and others. CVE-2026-80926 has not been confirmed as actively exploited and is not listed in the CISA KEV catalog.

  • What is the CVSS score for CVE-2026-80926?

    CVE-2026-80926 has a CVSS score of 9.8 out of 10, rated Critical severity (CVSS 3.1). The vector string is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H .

  • Is there a patch available for CVE-2026-80926?

    Yes. CVE-2026-80926 has been patched. Fixed versions include 6.6.158, 6.12.111, 6.18.51 and others. If you are running Linux kernel 6.6.143 or later up to the fix versions, apply the relevant patch for your kernel branch.

  • Is CVE-2026-80926 actively exploited?

    No. CVE-2026-80926 has not been confirmed as actively exploited. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.