CVE-2026-43379
published 2026-05-08CVE-2026-43379: In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in smb_lazy_parent_lease_break_close() opinfo pointer obtained…
PriorityP346critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.44%
36.5th percentile
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: fix use-after-free in smb_lazy_parent_lease_break_close()
opinfo pointer obtained via rcu_dereference(fp->f_opinfo) is being
accessed after rcu_read_unlock() has been called. This creates a
race condition where the memory could be freed by a concurrent
writer between the unlock and the subsequent pointer dereferences
(opinfo->is_lease, etc.), leading to a use-after-free.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| linux | linux | — | — |
| linux | linux | >= 27b40b7bfcd121fe13a150ffe11957630cf49246 < bf4d66d72e4a9e268c1012c331ce9eaedb5e2086 | bf4d66d72e4a9e268c1012c331ce9eaedb5e2086 |
| linux | linux | >= 5fb282ba4fef8985a5acf2b32681f2ec07732561 < 960699317d39f46611f4ebeb69edc567c1f4e6b6 | 960699317d39f46611f4ebeb69edc567c1f4e6b6 |
| linux | linux | >= 5fb282ba4fef8985a5acf2b32681f2ec07732561 < dbbd328cf58261ca239756fe1c0d10c9518d3399 | dbbd328cf58261ca239756fe1c0d10c9518d3399 |
| linux | linux | >= 5fb282ba4fef8985a5acf2b32681f2ec07732561 < b3568347c51c46e2cabc356bc34676df98296619 | b3568347c51c46e2cabc356bc34676df98296619 |
| linux | linux | >= 5fb282ba4fef8985a5acf2b32681f2ec07732561 < eac3361e3d5dd8067b3258c69615888eb45e9f25 | eac3361e3d5dd8067b3258c69615888eb45e9f25 |
| linux | linux | >= 6.6.32 < 6.6.130 | 6.6.130 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 6.13 < 6.18.19 | 6.18.19 |
| linux | linux_kernel | >= 6.19 < 6.19.9 | 6.19.9 |
| linux | linux_kernel | >= 6.6.32 < 6.6.130 | 6.6.130 |
| linux | linux_kernel | >= 6.9 < 6.12.78 | 6.12.78 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wvq8-6v44-2qvw: In the Linux kernel, the following vulnerability has been resolved:
ksmbd: fix use-after-free in smb_lazy_parent_lease_break_close()
opinfo pointer
ghsa_unreviewed·2026-05-08
CVE-2026-43379 GHSA-wvq8-6v44-2qvw: In the Linux kernel, the following vulnerability has been resolved:
ksmbd: fix use-after-free in smb_lazy_parent_lease_break_close()
opinfo pointer
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: fix use-after-free in smb_lazy_parent_lease_break_close()
opinfo pointer obtained via rcu_dereference(fp->f_opinfo) is being
accessed after rcu_read_unlock() has been called. This creates a
race condition where the memory could be freed by a concurrent
writer between the unlock and the subsequent pointer dereferences
(opinfo->is_lease, etc.), leading to a use-after-free.
Red Hat
kernel: ksmbd: fix use-after-free in smb_lazy_parent_lease_break_close()
vendor_redhat·2026-05-08
CVE-2026-43379 CWE-825 kernel: ksmbd: fix use-after-free in smb_lazy_parent_lease_break_close()
kernel: ksmbd: fix use-after-free in smb_lazy_parent_lease_break_close()
A flaw was found in ksmbd, a component of the Linux kernel. A race condition exists where a pointer to `opinfo` is accessed after its associated memory may have been freed by a concurrent operation. This use-after-free vulnerability can lead to memory corruption, potentially causing system instability or a denial of service (DoS).
Package: kernel (Red Hat Enterprise Linux 10) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Not affected
Package: kernel (Red Hat Enterprise Linux 8) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 8) - Not affected
Package: kernel (Re
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/960699317d39f46611f4ebeb69edc567c1f4e6b6https://git.kernel.org/stable/c/b3568347c51c46e2cabc356bc34676df98296619https://git.kernel.org/stable/c/bf4d66d72e4a9e268c1012c331ce9eaedb5e2086https://git.kernel.org/stable/c/dbbd328cf58261ca239756fe1c0d10c9518d3399https://git.kernel.org/stable/c/eac3361e3d5dd8067b3258c69615888eb45e9f25
2026-05-08
Published