CVE-2026-31444
published 2026-04-22CVE-2026-31444: In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free and NULL deref in smb_grant_oplock() smb_grant_oplock() has two…
PriorityP344critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.45%
36.9th percentile
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: fix use-after-free and NULL deref in smb_grant_oplock()
smb_grant_oplock() has two issues in the oplock publication sequence:
1) opinfo is linked into ci->m_op_list (via opinfo_add) before
add_lease_global_list() is called. If add_lease_global_list()
fails (kmalloc returns NULL), the error path frees the opinfo
via __free_opinfo() while it is still linked in ci->m_op_list.
Concurrent m_op_list readers (opinfo_get_list, or direct iteration
in smb_break_all_levII_oplock) dereference the freed node.
2) opinfo->o_fp is assigned after add_lease_global_list() publishes
the opinfo on the global lease list. A concurrent
find_same_lease_key() can walk the lease list and dereference
opinfo->o_fp->f_ci while o_fp is still NULL.
Fix by restructuring the publication sequence to eliminate post-publish
failure:
- Set opinfo->o_fp before any list publication (fixes NULL deref).
- Preallocate lease_table via alloc_lease_table() before opinfo_add()
so add_lease_global_list() becomes infallible after publication.
- Keep the original m_op_list publication order (opinfo_add before
lease list) so concurrent opens via same_client_has_lease() and
opinfo_get_list() still see the in-flight grant.
- Use opinfo_put() instead of __free_opinfo() on err_out so that
the RCU-deferred free path is used.
This also requires splitting add_lease_global_list() to take a
preallocated lease_table and changing its return type from int to void,
since it can no longer fail.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| linux | linux | >= 08aa9f3c8cf4d0bee44df540dfe34e8d64069f2c < 7de55bba69cbf0f9280daaea385daf08bc076121 | 7de55bba69cbf0f9280daaea385daf08bc076121 |
| linux | linux | >= 1d6abf145615dbfe267ce3b0a271f95e3780e18e < a5c6f6d6ceefed2d5210ee420fb75f8362461f46 | a5c6f6d6ceefed2d5210ee420fb75f8362461f46 |
| linux | linux | >= 1dfd062caa165ec9d7ee0823087930f3ab8a6294 < 48623ec358c1c600fa1e38368746f933e0f1a617 | 48623ec358c1c600fa1e38368746f933e0f1a617 |
| linux | linux | >= 302fef75512b2c8329a3f5efab1ae7ba2562387a < 9e785f004cbc56390479b77375726ea9b0d1a8a6 | 9e785f004cbc56390479b77375726ea9b0d1a8a6 |
| linux | linux | >= 6.12.78 < 6.12.80 | 6.12.80 |
| linux | linux | >= 6.18.19 < 6.18.21 | 6.18.21 |
| linux | linux | >= 6.19.9 < 6.19.11 | 6.19.11 |
| linux | linux | >= 6.6.130 < 6.6.131 | 6.6.131 |
| linux | linux | >= ce8507ee82c888126d8e7565e27c016308d24cde < 6d7e5a918c1d0aad06db0e17677b66fc9a471021 | 6d7e5a918c1d0aad06db0e17677b66fc9a471021 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 6.12.78 < 6.12.80 | 6.12.80 |
| linux | linux_kernel | >= 6.18.19 < 6.18.21 | 6.18.21 |
| linux | linux_kernel | >= 6.19.9 < 6.19.11 | 6.19.11 |
| ubuntu | linux-gcp-6.17 | — | — |
| ubuntu | linux-oem-6.17 | — | — |
| ubuntu | linux-oracle-6.17 | — | — |
| ubuntu | linux-realtime-6.17 | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Linux Kernel up to 6.6.130/6.12.79/6.18.20/6.19.10 smb_grant_oplock use after free (WID-SEC-2026-1252)
vuldb·2026-04-23
CVE-2026-31444 [CRITICAL] Linux Kernel up to 6.6.130/6.12.79/6.18.20/6.19.10 smb_grant_oplock use after free (WID-SEC-2026-1252)
A vulnerability, which was classified as critical, was found in Linux Kernel up to 6.6.130/6.12.79/6.18.20/6.19.10. This impacts the function smb_grant_oplock. Executing a manipulation can lead to use after free.
This vulnerability is handled as CVE-2026-31444. The attack can only be done within the local network. There is not any exploit available.
You should upgrade the affected component.
GHSA
GHSA-8vw8-r4jr-vp93: In the Linux kernel, the following vulnerability has been resolved:
ksmbd: fix use-after-free and NULL deref in smb_grant_oplock()
smb_grant_oplock(
ghsa_unreviewed·2026-04-22
CVE-2026-31444 GHSA-8vw8-r4jr-vp93: In the Linux kernel, the following vulnerability has been resolved:
ksmbd: fix use-after-free and NULL deref in smb_grant_oplock()
smb_grant_oplock(
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: fix use-after-free and NULL deref in smb_grant_oplock()
smb_grant_oplock() has two issues in the oplock publication sequence:
1) opinfo is linked into ci->m_op_list (via opinfo_add) before
add_lease_global_list() is called. If add_lease_global_list()
fails (kmalloc returns NULL), the error path frees the opinfo
via __free_opinfo() while it is still linked in ci->m_op_list.
Concurrent m_op_list readers (opinfo_get_list, or direct iteration
in smb_break_all_levII_oplock) dereference the freed node.
2) opinfo->o_fp is assigned after add_lease_global_list() publishes
the opinfo on the global lease list. A concurrent
find_same_lease_key() can walk the lease list and dereference
opinfo->o_fp->f_ci while o_fp is still
Ubuntu
Linux kernel (Oracle) vulnerabilities
vendor_ubuntu·2026-07-28
CVE-2026-23057 Linux kernel (Oracle) vulnerabilities
Title: Linux kernel (Oracle) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- Foo-over-UDP (FOU);
- ARM64 architecture;
- x86 architecture;
- Block layer subsystem;
- Drivers core;
- Null block device driver;
- Bluetooth drivers;
- Counter interface drivers;
- DMA engine subsystem;
- DPLL subsystem;
- GPIO subsystem;
- GPU drivers;
- I2C subsystem;
- IIO ADC drivers;
- IIO subsystem;
- On-Chip Interconnect management framework;
- IOMMU subsystem;
- IRQ chip drivers;
- Modular ISDN driver;
- LED subsystem;
- Multiple devices driver;
- UACCE accelerator framework;
- MMC subsystem
Ubuntu
Linux kernel (OEM) vulnerabilities
vendor_ubuntu·2026-07-23
CVE-2025-71190 Linux kernel (OEM) vulnerabilities
Title: Linux kernel (OEM) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- Foo-over-UDP (FOU);
- ARM64 architecture;
- x86 architecture;
- Block layer subsystem;
- Drivers core;
- Null block device driver;
- Bluetooth drivers;
- Counter interface drivers;
- DMA engine subsystem;
- DPLL subsystem;
- GPIO subsystem;
- GPU drivers;
- I2C subsystem;
- IIO ADC drivers;
- IIO subsystem;
- On-Chip Interconnect management framework;
- IOMMU subsystem;
- IRQ chip drivers;
- Modular ISDN driver;
- LED subsystem;
- Multiple devices driver;
- UACCE accelerator framework;
- MMC subsystem;
-
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2026-07-20
CVE-2025-71190 Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- Foo-over-UDP (FOU);
- ARM64 architecture;
- x86 architecture;
- Block layer subsystem;
- Drivers core;
- Null block device driver;
- Bluetooth drivers;
- Counter interface drivers;
- DMA engine subsystem;
- DPLL subsystem;
- GPIO subsystem;
- GPU drivers;
- I2C subsystem;
- IIO ADC drivers;
- IIO subsystem;
- On-Chip Interconnect management framework;
- IOMMU subsystem;
- IRQ chip drivers;
- Modular ISDN driver;
- LED subsystem;
- Multiple devices driver;
- UACCE accelerator framework;
- MMC subsystem;
- Ether
Red Hat
kernel: ksmbd: fix use-after-free and NULL deref in smb_grant_oplock()
vendor_redhat·2026-04-22
CVE-2026-31444 CWE-476 kernel: ksmbd: fix use-after-free and NULL deref in smb_grant_oplock()
kernel: ksmbd: fix use-after-free and NULL deref in smb_grant_oplock()
A flaw was found in ksmbd, a component of the Linux kernel. This vulnerability involves a use-after-free and a NULL pointer dereference within the `smb_grant_oplock()` function during the oplock publication sequence. An attacker could potentially exploit these issues, leading to memory corruption. This could result in a denial of service (DoS) due to system instability or crashes.
Package: kernel (Red Hat Enterprise Linux 10) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Not affected
Package: kernel (Red Hat Enterprise Linux 8) - Not affected
Package: kernel-rt (Red Hat Enterp
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/48623ec358c1c600fa1e38368746f933e0f1a617https://git.kernel.org/stable/c/6d7e5a918c1d0aad06db0e17677b66fc9a471021https://git.kernel.org/stable/c/7de55bba69cbf0f9280daaea385daf08bc076121https://git.kernel.org/stable/c/9e785f004cbc56390479b77375726ea9b0d1a8a6https://git.kernel.org/stable/c/a5c6f6d6ceefed2d5210ee420fb75f8362461f46
2026-04-22
Published