In the Linux kernel, the following vulnerability has been resolved:
ksmbd: fix use-after-free in smb_lazy_parent_lease_break_close()
opinfo pointer obtained via rcu_dereference(fp->f_opinfo) is being
accessed after rcu_read_unlock() has been called. This creates a
race condition where the memory could be freed by a concurrent
writer between the unlock and the subsequent pointer dereferences
(opinfo->is_lease, etc.), leading to a use-after-free.
References
Configurations
Configuration 1 (hide)
|
History
19 May 2026, 19:56
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://git.kernel.org/stable/c/960699317d39f46611f4ebeb69edc567c1f4e6b6 - Patch | |
| References | () https://git.kernel.org/stable/c/b3568347c51c46e2cabc356bc34676df98296619 - Patch | |
| References | () https://git.kernel.org/stable/c/bf4d66d72e4a9e268c1012c331ce9eaedb5e2086 - Patch | |
| References | () https://git.kernel.org/stable/c/dbbd328cf58261ca239756fe1c0d10c9518d3399 - Patch | |
| References | () https://git.kernel.org/stable/c/eac3361e3d5dd8067b3258c69615888eb45e9f25 - Patch | |
| CPE | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:7.0:rc1:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:7.0:rc3:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:7.0:rc2:*:*:*:*:*:* |
|
| First Time |
Linux linux Kernel
Linux |
|
| CWE | CWE-416 |
11 May 2026, 08:16
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
08 May 2026, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-08 15:16
Updated : 2026-05-19 19:56
NVD link : CVE-2026-43379
Mitre link : CVE-2026-43379
CVE.ORG link : CVE-2026-43379
JSON object : View
Products Affected
linux
- linux_kernel
CWE
CWE-416
Use After Free
