cbcvebase.
CVE-2026-43378
published 2026-05-08

CVE-2026-43378: In the Linux kernel, the following vulnerability has been resolved: smb: server: fix use-after-free in smb2_open() The opinfo pointer obtained via…

PriorityP340high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.31%
22.8th percentile
In the Linux kernel, the following vulnerability has been resolved: smb: server: fix use-after-free in smb2_open() The opinfo pointer obtained via rcu_dereference(fp->f_opinfo) is dereferenced after rcu_read_unlock(), creating a use-after-free window.

Affected

42 ranges· showing 25
VendorProductVersion rangeFixed in
linuxlinux
linuxlinux>= e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 < e1b21e6066615e7d3d3a7aa2677e415e563fd7cce1b21e6066615e7d3d3a7aa2677e415e563fd7cc
linuxlinux>= e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 < b720c84087cb547f23ce03eab93568c1769e4556b720c84087cb547f23ce03eab93568c1769e4556
linuxlinux>= e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 < 54b48ae83de8bb06e65079d96368efe359d4909c54b48ae83de8bb06e65079d96368efe359d4909c
linuxlinux>= e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 < 8f5b1a7cb009a93c48e9e334a2f59a660f9afc078f5b1a7cb009a93c48e9e334a2f59a660f9afc07
linuxlinux>= e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 < 190e5f808e8058640b408ccfed25440b441a718a190e5f808e8058640b408ccfed25440b441a718a
linuxlinux>= e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 < 1e689a56173827669a35da7cb2a3c78ed5c536801e689a56173827669a35da7cb2a3c78ed5c53680
linuxlinux_kernel
linuxlinux_kernel>= 5.15 < 6.1.1676.1.167
linuxlinux_kernel>= 6.13 < 6.18.196.18.19
linuxlinux_kernel>= 6.19 < 6.19.96.19.9
linuxlinux_kernel>= 6.2 < 6.6.1306.6.130
linuxlinux_kernel>= 6.7 < 6.12.786.12.78
ubuntulinux
ubuntulinux-aws
ubuntulinux-aws-6.8
ubuntulinux-aws-fips
ubuntulinux-azure-fips
ubuntulinux-fips
ubuntulinux-gcp
ubuntulinux-gcp-6.8
ubuntulinux-gcp-fips
ubuntulinux-gke
ubuntulinux-gkeop
ubuntulinux-hwe-6.17

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_ubuntu8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.