cbcvebase.
CVE-2026-43379
published 2026-05-08

CVE-2026-43379: In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in smb_lazy_parent_lease_break_close() opinfo pointer obtained…

PriorityP346critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.44%
36.5th percentile
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in smb_lazy_parent_lease_break_close() opinfo pointer obtained via rcu_dereference(fp->f_opinfo) is being accessed after rcu_read_unlock() has been called. This creates a race condition where the memory could be freed by a concurrent writer between the unlock and the subsequent pointer dereferences (opinfo->is_lease, etc.), leading to a use-after-free.

Affected

12 ranges
VendorProductVersion rangeFixed in
linuxlinux
linuxlinux>= 27b40b7bfcd121fe13a150ffe11957630cf49246 < bf4d66d72e4a9e268c1012c331ce9eaedb5e2086bf4d66d72e4a9e268c1012c331ce9eaedb5e2086
linuxlinux>= 5fb282ba4fef8985a5acf2b32681f2ec07732561 < 960699317d39f46611f4ebeb69edc567c1f4e6b6960699317d39f46611f4ebeb69edc567c1f4e6b6
linuxlinux>= 5fb282ba4fef8985a5acf2b32681f2ec07732561 < dbbd328cf58261ca239756fe1c0d10c9518d3399dbbd328cf58261ca239756fe1c0d10c9518d3399
linuxlinux>= 5fb282ba4fef8985a5acf2b32681f2ec07732561 < b3568347c51c46e2cabc356bc34676df98296619b3568347c51c46e2cabc356bc34676df98296619
linuxlinux>= 5fb282ba4fef8985a5acf2b32681f2ec07732561 < eac3361e3d5dd8067b3258c69615888eb45e9f25eac3361e3d5dd8067b3258c69615888eb45e9f25
linuxlinux>= 6.6.32 < 6.6.1306.6.130
linuxlinux_kernel
linuxlinux_kernel>= 6.13 < 6.18.196.18.19
linuxlinux_kernel>= 6.19 < 6.19.96.19.9
linuxlinux_kernel>= 6.6.32 < 6.6.1306.6.130
linuxlinux_kernel>= 6.9 < 6.12.786.12.78
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.