← Back to CVE List
CVE-2026-90156NVD
Vulnerability Summary
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: safely discard unregistered deferred locks
When vfs_lock_file() defers a lock, smb2_lock() puts its ksmbd_lock on
rollback_list before allocating and registering the asynchronous work.
If either operation fails, rollback assumes that smb_lock->conn is
initialized and dereferences NULL. The deferred file_lock also remains
linked into the VFS blocked-lock state while it is freed.
Keep the lock off rollback_list until async setup succeeds. On setup
failures, explicitly unblock and wake the deferred lock before freeing it
and its ksmbd wrapper.
ksmbd: safely discard unregistered deferred locks
When vfs_lock_file() defers a lock, smb2_lock() puts its ksmbd_lock on
rollback_list before allocating and registering the asynchronous work.
If either operation fails, rollback assumes that smb_lock->conn is
initialized and dereferences NULL. The deferred file_lock also remains
linked into the VFS blocked-lock state while it is freed.
Keep the lock off rollback_list until async setup succeeds. On setup
failures, explicitly unblock and wake the deferred lock before freeing it
and its ksmbd wrapper.
Affected & Patched Versions
- Linux Linux >= e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 and < d09af9a35ff7b77a950b507133d9092aadbfeff4
- Linux Linux >= e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 and < 054bcca4cd9f00719b01f7108b51a2168fb94f15
- Linux Linux >= 5.15
- Linux Linux d09af9a35ff7b77a950b507133d9092aadbfeff4
- Linux Linux 054bcca4cd9f00719b01f7108b51a2168fb94f15