{"id":"CVE-2026-89635","title":"kernel: ksmbd: only rebind the reopened file's own oplock on durable reconnect (CVE-2026-89635)","summary":"A flaw was found in ksmbd, a component of the Linux kernel. An authenticated attacker could exploit a use-after-free vulnerability by manipulating durable handles and oplocks during session reconnection. When two sessions hold durable hand…","severity":"medium","cvss":5.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","cvssSource":"vendor","cwe":"CWE-825","vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","affected":["openshift_container_platform 4"],"published":"2026-09-11","updated":"2026-09-15","sourceUpdated":"2026-09-15T06:18:57+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89635.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89635.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-89635"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2532506"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-89635"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89635"},{"url":"https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-89635.mbox"},{"url":"https://git.kernel.org/stable/c/3f220a0a62e6b9b391c9d1f0e6580b05173cc7f7"},{"url":"https://git.kernel.org/stable/c/74e3ef4630f004c0de40c0540648a5a4033c6c9d"}],"tags":["csaf","vex","red-hat","cve.org","score-dispute"],"epss":0.00553,"epssPercentile":0.45058,"scores":{"vendor":5.3,"cna":9.8},"ingestedAt":"2026-09-14T15:23:07.474Z","slug":"CVE-2026-89635","body":"## Overview\n\nA flaw was found in ksmbd, a component of the Linux kernel. An authenticated attacker could exploit a use-after-free vulnerability by manipulating durable handles and oplocks during session reconnection. When two sessions hold durable handles on the same file and both disconnect, reconnecting one of them can incorrectly adopt the other session's oplock. If the adopting session is then destroyed, the foreign oplock still points to the freed session, leading to a use-after-free when dereferenced. This can result in a system crash and a denial of service.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Moderate · updated 2026-09-15 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89635.json)\n\n**kernel: ksmbd: only rebind the reopened file's own oplock on durable reconnect** — rated Moderate by Red Hat. Released 2026-09-11, updated 2026-09-15.\n\nNot affected:\n\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 6\n- Red Hat Enterprise Linux 7\n- Red Hat Enterprise Linux 8\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift Container Platform 4\n\n## Remediation\n\nRefer to the advisory for fix availability.","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":30.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[{"seq":203945,"id":"CVE-2026-89635","ts":1789490230736,"field":"cvss","old":"5.3","new":"5.5"},{"seq":203009,"id":"CVE-2026-89635","ts":1789403733332,"field":"cvss","old":"9.8","new":"5.3"},{"seq":203008,"id":"CVE-2026-89635","ts":1789403733332,"field":"severity","old":"critical","new":"medium"},{"seq":197823,"id":"CVE-2026-89635","ts":1789384320548,"field":"cvss","old":"5.3","new":"9.8"},{"seq":197822,"id":"CVE-2026-89635","ts":1789384320548,"field":"severity","old":"medium","new":"critical"},{"seq":183725,"id":"CVE-2026-89635","ts":1789356677116,"field":"cvss","old":"9.8","new":"5.3"},{"seq":183724,"id":"CVE-2026-89635","ts":1789356677116,"field":"severity","old":"critical","new":"medium"},{"seq":153474,"id":"CVE-2026-89635","ts":1789285350662,"field":"cvss","old":null,"new":"9.8"},{"seq":153473,"id":"CVE-2026-89635","ts":1789285350662,"field":"severity","old":"none","new":"critical"},{"seq":147147,"id":"CVE-2026-89635","ts":1789270196938,"field":"cvss","old":null,"new":"5.3"},{"seq":147146,"id":"CVE-2026-89635","ts":1789270196938,"field":"severity","old":"none","new":"medium"},{"seq":108902,"id":"CVE-2026-89635","ts":1789183729472,"field":"cvss","old":null,"new":"5.3"},{"seq":108901,"id":"CVE-2026-89635","ts":1789183729472,"field":"severity","old":"none","new":"medium"}]}