Answer in brief
CVE-2026-43376 records a Unknown severity vulnerability in ksmbd: fix use-after-free by using call_rcu() for oplock_info. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=296cb5457cc6f4a754c4ae29855f8a253d52bcc6 <302fef75512b2c8329a3f5efab1ae7ba2562387a || >=d54ab1520d43e95f9b2e22d7a05fc9614192e5a5 <08aa9f3c8cf4d0bee44df540dfe34e8d64069f2c || >=18b4fac5ef17f77fed9417d22210ceafd6525fc7 <1d6abf145615dbfe267ce3b0a271f95e3780e18e || >=18b4fac5ef17f77fed9417d22210ceafd6525fc7 <ce8507ee82c888126d8e7565e27c016308d24cde || >=18b4fac5ef17f77fed9417d22210ceafd6525fc7 <1dfd062caa165ec9d7ee0823087930f3ab8a6294 || d73686367ad68534257cd88a36ca3c52cb8b81d8 || >=6.6.88 <6.6.130 || >=6.12.25 <6.12.78 || >=6.14.4 <6.15 | 302fef75512b2c8329a3f5efab1ae7ba2562387a, 08aa9f3c8cf4d0bee44df540dfe34e8d64069f2c, 1d6abf145615dbfe267ce3b0a271f95e3780e18e, ce8507ee82c888126d8e7565e27c016308d24cde, 1dfd062caa165ec9d7ee0823087930f3ab8a6294, 6.6.130, 6.12.78, 6.15 |
| Linux/Linuxgeneric | 6.15 | Not reported |
Published upstream
May 8, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free by using call_rcu() for oplock_info ksmbd currently frees oplock_info immediately using kfree(), even though it is accessed under RCU read-side critical sections in places like opinfo_get() and proc_show_files(). Since there is no RCU grace period delay between nullifying the pointer and freeing the memory, a reader can still access oplock_info structure after it has been freed. This can leads to a use-after-free especially in opinfo_get() where atomic_inc_not_zero() is called on already freed memory. Fix this by switching to deferred freeing using call_rcu().
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2026-43376 records a Unknown severity vulnerability in ksmbd: fix use-after-free by using call_rcu() for oplock_info. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=296cb5457cc6f4a754c4ae29855f8a253d52bcc6 <302fef75512b2c8329a3f5efab1ae7ba2562387a || >=d54ab1520d43e95f9b2e22d7a05fc9614192e5a5 <08aa9f3c8cf4d0bee44df540dfe34e8d64069f2c || >=18b4fac5ef17f77fed9417d22210ceafd6525fc7 <1d6abf145615dbfe267ce3b0a271f95e3780e18e || >=18b4fac5ef17f77fed9417d22210ceafd6525fc7 <ce8507ee82c888126d8e7565e27c016308d24cde || >=18b4fac5ef17f77fed9417d22210ceafd6525fc7 <1dfd062caa165ec9d7ee0823087930f3ab8a6294 || d73686367ad68534257cd88a36ca3c52cb8b81d8 || >=6.6.88 <6.6.130 || >=6.12.25 <6.12.78 || >=6.14.4 <6.15 | 302fef75512b2c8329a3f5efab1ae7ba2562387a, 08aa9f3c8cf4d0bee44df540dfe34e8d64069f2c, 1d6abf145615dbfe267ce3b0a271f95e3780e18e, ce8507ee82c888126d8e7565e27c016308d24cde, 1dfd062caa165ec9d7ee0823087930f3ab8a6294, 6.6.130, 6.12.78, 6.15 |
| Linux/Linuxgeneric | 6.15 | Not reported |
Published upstream
May 8, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free by using call_rcu() for oplock_info ksmbd currently frees oplock_info immediately using kfree(), even though it is accessed under RCU read-side critical sections in places like opinfo_get() and proc_show_files(). Since there is no RCU grace period delay between nullifying the pointer and freeing the memory, a reader can still access oplock_info structure after it has been freed. This can leads to a use-after-free especially in opinfo_get() where atomic_inc_not_zero() is called on already freed memory. Fix this by switching to deferred freeing using call_rcu().
Quoted source text, attributed separately from HOL analysis.