LIVE · cybersecurity feed
Live wire
cve recordcritical

CVE-2026-64142

linux · linux kernel

Published
CVSS9.8
Severitycritical
WeaknessCWE-416
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

In the Linux kernel, the following vulnerability has been resolved: ksmbd: close durable scavenger races against m_fp_list lookups ksmbd_durable_scavenger() has two related races against any walker that iterates f_ci->m_fp_list, including ksmbd_lookup_fd_inode() (used by ksmbd_vfs_rename) and the share-mode checks in fs/smb/server/smb_common.c. (1) fp->node list-head reuse. Durable-preserved handles can remain linked on f_ci->m_fp_list after session teardown so share-mode checks still see them while the handle is reconnectable. The scavenger collected expired handles by adding fp->node to a local scavenger_list after removing them from the global durable idr. Because fp->node is the sam

References

← Back to the CVE Tracker

Our coverage of CVE-2026-64142

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-64142.