{"id":"CVE-2026-90167","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: serialize oplock close with pending break ownership\n\nclose may abort an in-flight oplock break while another breaker already\nholds an opinfo reference","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: serialize oplock close with pending break ownership\n\nclose may abort an in-flight oplock break while another breaker already\nholds an opinfo reference. Releasing…","severity":"none","vendor":"Linux","product":"Linux","affected":["Linux >= e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 < 5f97bac88bfb333f426f01c118b8235e75af8d96","Linux >= e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 < b0148dc5625dbfd50596ac63c7487c12e8a8ab03","Linux 5.15"],"published":"2026-09-17","updated":"2026-09-17","sourceUpdated":"2026-09-17T17:17:10.097","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-90167","references":[{"url":"https://git.kernel.org/stable/c/5f97bac88bfb333f426f01c118b8235e75af8d96","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b0148dc5625dbfd50596ac63c7487c12e8a8ab03","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-17T16:21:47.871Z","epss":0.00189,"epssPercentile":0.08857,"slug":"CVE-2026-90167","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: serialize oplock close with pending break ownership\n\nclose may abort an in-flight oplock break while another breaker already\nholds an opinfo reference. Releasing pending_break wakes that waiter, but\nwithout serializing the close transition with bit acquisition it can become\na new break owner through the test_and_set_bit() fast path. It can then\noverwrite OPLOCK_CLOSING with OPLOCK_ACK_WAIT and continue a break for\na dying opinfo.\n\nMake OPLOCK_CLOSING terminal once the opinfo is removed from the inode\nlist. Serialize that transition, pending_break acquisition, and\nOPLOCK_ACK_WAIT setup with an opinfo state lock. A breaker which loses\nthe race releases its ownership and returns -ENOENT. Explicitly wake\npending_break waiters during close so they can observe the terminal state.\n\nAlso prevent ACK and timeout paths from replacing OPLOCK_CLOSING with\nOPLOCK_STATE_NONE.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}