Review reviewHigh

CVE-2026-64437

Linux

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free of a deferred file_lock on SMB2_CLOSE then SMB2_CANCEL Commit f580d27e8928 ("ksmbd: fix use-after-free of a deferred file_lock on double SMB2_CANCEL") made smb2_cancel() skip a work whose state is KSMBD_WORK_CANCELLED, so its cancel_fn cannot be fired a second time. But KSMBD_WORK has three states (ACTIVE, CANCELLED, CLOSED), and the same freeing producer path is reached for CLOSED too: SMB2_CLOSE on the locking handle -> set_close_state_blocked_works() sets the deferred work's state to KSMBD_WORK_...

CVSS
8.8
EPSS
-
- percentile
CISA KEV
Not listed
Published
2026.07.25
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability-
Technical severityCVSS 8.8

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free of a deferred file_lock on SMB2_CLOSE then SMB2_CANCEL Commit f580d27e8928 ("ksmbd: fix use-after-free of a deferred file_lock on double SMB2_CANCEL") made smb2_cancel() skip a work whose state is KSMBD_WORK_CANCELLED, so its cancel_fn cannot be fired a second time. But KSMBD_WORK has three states (ACTIVE, CANCELLED, CLOSED), and the same freeing producer path is reached for CLOSED too: SMB2_CLOSE on the locking handle -> set_close_state_blocked_works() sets the deferred work's state to KSMBD_WORK_...

Affected product and versions

Product
Linux
Affected versions
>= b7063c7426ea5a4d15e01b60538718765392f49d < a796ba4e61d5e14e07b79a359faac69f8f9b22a3, >= 0da2e073f9cbf4985a0fd9acb71bc5ff599f8afd < b8e274e69ab09222c7a552c7c0c1eef9ce627fc1, >= 89ae9df09d2c1fb4a4eb495c113a7ce1dca34147 < ddb9239828336b36d8a3ef5943fdffb2f55b6508, >= 14d2eee0193ac3cd1bf3d014373449f0b8d35d6d < 94083db751930b1540ddff2b54d4677549c57f81, >= f580d27e8928828693df44ba2db0fffdbe11dfea < 12c36c99655f325befe50c26842f7deca414c381, >= f580d27e8928828693df44ba2db0fffdbe11dfea < 10f293a07f9e10e988b0ae44e2e99c631f5a68e0, >= 2b2eda2821cff1d1b5a423b6ee7d8fc6fbc8e694, >= 6.1.176 < 6.1.178, >= 6.6.143 < 6.6.145, >= 6.12.94 < 6.12.96, >= 6.18.36 < 6.18.39, >= 7.0.13 < 7.1, >= 7.1
Fixed versions
No verified fixed-version field is available yet

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE
Not available