« Volver al listado

CVE-2026-68381

Estado: RecibidaCrítica (9.8)—

In the Linux kernel, the following vulnerability has been resolved:

ksmbd: pin conn during async oplock break notification

smb2_oplock_break_noti() and smb2_lease_break_noti() store a ksmbd_conn pointer in an async ksmbd_work and then queue that work on ksmbd-io. The work only increments conn->r_count, which prevents teardown from passing the pending-request wait after the increment, but it does not pin the struct ksmbd_conn object.

If connection teardown races with an oplock break notification, the last conn reference can be dropped before the queued worker finishes. The worker then uses the freed conn in ksmbd_conn_write() and ksmbd_conn_r_count_dec().

Leer descripción completaMostrar menos

Take a real conn reference when publishing the conn pointer to the async work item, and drop it after the notification work has decremented r_count. Apply the same lifetime rule to lease break notification, which uses the same work->conn pattern.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

CVE critica en kernel Linux con AV:N (red sin privilegios). Carrera de condiciones en ksmbd (SMB server) permite liberación de memoria y ejecución de código arbitrario en contexto del kernel, lograble via protocolo SMB remoto.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-68381",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "09aeab68033161cb54f194da93e51a11aee6144b",
              "lessThan": "0f72fc9659d7f585460d43c158055df5afdcffb6",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "a4261bbc33fbf99b99c80aa3a2c5097611802980",
              "lessThan": "793e1c7041b93af96ff87e678329bc16aee7ba88",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "3aa660c059240e0c795217182cf7df32909dd917",
              "lessThan": "6ecb252efa0b413ac3d9979fb4eec247f8fc1258",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "3aa660c059240e0c795217182cf7df32909dd917",
              "lessThan": "14062c74e5b25c27edcff7a2fe0dc701c930b372",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "3aa660c059240e0c795217182cf7df32909dd917",
              "lessThan": "aa5d8f3f96aa11a4a54ce993c11ce8af11c546f9",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "f17d1c63a76b0fe8e9c78023a86507a3a6d62cfa",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "6.6.84",
              "lessThan": "6.6.148",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.12.20",
              "lessThan": "6.12.101",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.13.8",
              "lessThan": "6.14",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "fs/smb/server/oplock.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.14"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.14",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.6.148",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.101",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.42",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.1.6",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "fs/smb/server/oplock.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-08-10T13:20:31.197",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/0f72fc9659d7f585460d43c158055df5afdcffb6",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/14062c74e5b25c27edcff7a2fe0dc701c930b372",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/6ecb252efa0b413ac3d9979fb4eec247f8fc1258",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/793e1c7041b93af96ff87e678329bc16aee7ba88",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/aa5d8f3f96aa11a4a54ce993c11ce8af11c546f9",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: pin conn during async oplock break notification\n\nsmb2_oplock_break_noti() and smb2_lease_break_noti() store a ksmbd_conn\npointer in an async ksmbd_work and then queue that work on ksmbd-io.  The\nwork only increments conn->r_count, which prevents teardown from passing\nthe pending-request wait after the increment, but it does not pin the\nstruct ksmbd_conn object.\n\nIf connection teardown races with an oplock break notification, the last\nconn reference can be dropped before the queued worker finishes.  The\nworker then uses the freed conn in ksmbd_conn_write() and\nksmbd_conn_r_count_dec().\n\nTake a real conn reference when publishing the conn pointer to the async\nwork item, and drop it after the notification work has decremented\nr_count.  Apply the same lifetime rule to lease break notification, which\nuses the same work->conn pattern."
    }
  ],
  "lastModified": "2026-08-17T06:17:46.560",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}