CyberRota Analysis
AI-GeneratedA use-after-free vulnerability exists in the Linux kernel's ksmbd component, specifically within the same_client_has_lease() function, which improperly manages memory references when handling lease pointers. This flaw can lead to potential memory corruption and exploitation, particularly during concurrent operations, posing a risk to system stability and security. Organizations utilizing affected Linux systems, especially those relying on SMB protocol for file sharing, should prioritize patching to mitigate potential exploitation risks.
Original NVD Description
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in same_client_has_lease() same_client_has_lease() returns an opinfo pointer from ci->m_op_list after dropping ci->m_lock without taking a reference. smb_grant_oplock() then dereferences that pointer in copy_lease() and when checking breaking_cnt. A concurrent close can remove the old lease from ci->m_op_list and drop the last reference before the caller uses the returned pointer, leading to a use-after-free. Take a reference when same_client_has_lease() selects an existing lease, drop any previous match while scanning, and release the returned reference in smb_grant_oplock() after copying the lease state.