{"id":"CVE-2026-64016","title":"ksmbd: fix durable reconnect error path file lifetime","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: fix durable reconnect error path file lifetime\n\nAfter a durable reconnect succeeds, ksmbd_reopen_durable_fd() republishes\nthe same ksmbd_file into the session vo…","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cvssSource":"cna","vendor":"Linux","product":"Linux","affected":["Linux >= f0ff7f12398e85b3a11745ff7feab6246f3d75c2 < 5e641e4ee0bc1937408d41051a908ad4151be63b","Linux >= 4db3dcac84c2f14a45ae201efb38de1fb1bfc009 < 478bfaa036bd0c7e179acff8b8484bccdee3b8c7","Linux >= ce2e164c1c51c3f7813b80f8c926836e896bcbb3 < a1a39f227c80cbf369767badc32cba2b225147d1","Linux >= 97a0cd55283b4e63fd92804da91c8d9896adcad9 < 6cb0b9385320110fe24a5d5ac0000ade4bb3a3f3","Linux >= 1baff47b81f94f9231c91236aa511420d0e266b9 < 3515503322f4819277091839eed46b695096aca5","Linux >= 6.18.33 < 6.18.34","Linux >= 7.0.10 < 7.0.11"],"published":"2026-07-19","updated":"2026-09-14","sourceUpdated":"2026-09-14T11:58:34.345Z","source":"CVEORG","sourceUrl":"https://www.cve.org/CVERecord?id=CVE-2026-64016","references":[{"url":"https://git.kernel.org/stable/c/5e641e4ee0bc1937408d41051a908ad4151be63b"},{"url":"https://git.kernel.org/stable/c/478bfaa036bd0c7e179acff8b8484bccdee3b8c7"},{"url":"https://git.kernel.org/stable/c/a1a39f227c80cbf369767badc32cba2b225147d1"},{"url":"https://git.kernel.org/stable/c/6cb0b9385320110fe24a5d5ac0000ade4bb3a3f3"},{"url":"https://git.kernel.org/stable/c/3515503322f4819277091839eed46b695096aca5"}],"tags":["cve.org"],"epss":0.00671,"epssPercentile":0.50595,"ingestedAt":"2026-09-14T15:23:07.457Z","slug":"CVE-2026-64016","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: fix durable reconnect error path file lifetime\n\nAfter a durable reconnect succeeds, ksmbd_reopen_durable_fd() republishes\nthe same ksmbd_file into the session volatile-id table. If smb2_open()\nthen takes a later error path, cleanup first calls ksmbd_fd_put(work, fp)\nand then unconditionally calls ksmbd_put_durable_fd(dh_info.fp).\n\nIn this case fp and dh_info.fp are the same object. The first put drops the\nreconnect lookup reference, but the final durable put can run\n__ksmbd_close_fd(NULL, fp). Because the final close is not session-aware,\nit can free the file object without removing the volatile-id entry that was\njust published into the session table.\n\nUse the session-aware put for the final reconnect drop when the reconnect\nhad already succeeded and the error path is cleaning up the republished\nfile. Earlier reconnect failures, before fp is assigned to dh_info.fp, keep\nusing the durable-only put path.\n\n## Affected\n\n- `Linux >= f0ff7f12398e85b3a11745ff7feab6246f3d75c2 < 5e641e4ee0bc1937408d41051a908ad4151be63b`\n- `Linux >= 4db3dcac84c2f14a45ae201efb38de1fb1bfc009 < 478bfaa036bd0c7e179acff8b8484bccdee3b8c7`\n- `Linux >= ce2e164c1c51c3f7813b80f8c926836e896bcbb3 < a1a39f227c80cbf369767badc32cba2b225147d1`\n- `Linux >= 97a0cd55283b4e63fd92804da91c8d9896adcad9 < 6cb0b9385320110fe24a5d5ac0000ade4bb3a3f3`\n- `Linux >= 1baff47b81f94f9231c91236aa511420d0e266b9 < 3515503322f4819277091839eed46b695096aca5`\n- `Linux >= 6.18.33 < 6.18.34`\n- `Linux >= 7.0.10 < 7.0.11`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":54,"depthScoreParts":{"impact":53.9,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}