CVE-2026-90156
In the Linux kernel, the following vulnerability has been resolved: ksmbd: safely discard unregistered deferred locks When vfs_lock_file() defers a lock, smb2_lock() puts its ksmbd_lock on rollback_list before allocating and registering the asynchronous work. If either operation fails, rollback assumes that smb_lock->conn is initialized and dereferences NULL. The deferred file_lock also remains linked into the VFS blocked-lock state while it is freed. Keep the lock off rollback_list until async setup succeeds. On setup failures, explicitly unblock and wake the deferred lock before freeing it and its ksmbd wrapper.
Affected versions
Linux kernel versions
5.15
and later are affected. Fixed in
7.2.6,
7.3-rc1
and their respective stable series.
References
2 totalFrequently asked questions
-
What is CVE-2026-90156?
CVE-2026-90156 is a unscored severity Linux kernel vulnerability . It affects Linux kernel versions from 5.15 onward and has been patched in 7.2.6 and 7.3-rc1. CVE-2026-90156 has not been confirmed as actively exploited and is not listed in the CISA KEV catalog.
-
Is there a patch available for CVE-2026-90156?
Yes. CVE-2026-90156 has been patched. Fixed versions include 7.2.6 and 7.3-rc1. If you are running Linux kernel 5.15 or later up to the fix versions, apply the relevant patch for your kernel branch.
-
Is CVE-2026-90156 actively exploited?
No. CVE-2026-90156 has not been confirmed as actively exploited. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.