Answer in brief
CVE-2026-64437 records a Unknown severity vulnerability in ksmbd: fix use-after-free of a deferred file_lock on SMB2_CLOSE then SMB2_CANCEL. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
Answer in brief
CVE-2026-64437 records a Unknown severity vulnerability in ksmbd: fix use-after-free of a deferred file_lock on SMB2_CLOSE then SMB2_CANCEL. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=b7063c7426ea5a4d15e01b60538718765392f49d <a796ba4e61d5e14e07b79a359faac69f8f9b22a3 || >=0da2e073f9cbf4985a0fd9acb71bc5ff599f8afd <b8e274e69ab09222c7a552c7c0c1eef9ce627fc1 || >=89ae9df09d2c1fb4a4eb495c113a7ce1dca34147 <ddb9239828336b36d8a3ef5943fdffb2f55b6508 || >=14d2eee0193ac3cd1bf3d014373449f0b8d35d6d <94083db751930b1540ddff2b54d4677549c57f81 || >=f580d27e8928828693df44ba2db0fffdbe11dfea <12c36c99655f325befe50c26842f7deca414c381 || >=f580d27e8928828693df44ba2db0fffdbe11dfea <10f293a07f9e10e988b0ae44e2e99c631f5a68e0 || 2b2eda2821cff1d1b5a423b6ee7d8fc6fbc8e694 || >=6.1.176 <6.1.178 || >=6.6.143 <6.6.145 || >=6.12.94 <6.12.96 || >=6.18.36 <6.18.39 || >=7.0.13 <7.1 | a796ba4e61d5e14e07b79a359faac69f8f9b22a3, b8e274e69ab09222c7a552c7c0c1eef9ce627fc1, ddb9239828336b36d8a3ef5943fdffb2f55b6508, 94083db751930b1540ddff2b54d4677549c57f81, 12c36c99655f325befe50c26842f7deca414c381, 10f293a07f9e10e988b0ae44e2e99c631f5a68e0, 6.1.178, 6.6.145, 6.12.96, 6.18.39, 7.1 |
| Linux/Linuxgeneric | 7.1 | Not reported |
Published upstream
Jul 25, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free of a deferred file_lock on SMB2_CLOSE then SMB2_CANCEL Commit f580d27e8928 ("ksmbd: fix use-after-free of a deferred file_lock on double SMB2_CANCEL") made smb2_cancel() skip a work whose state is KSMBD_WORK_CANCELLED, so its cancel_fn cannot be fired a second time. But KSMBD_WORK has three states (ACTIVE, CANCELLED, CLOSED), and the same freeing producer path is reached for CLOSED too: SMB2_CLOSE on the locking handle -> set_close_state_blocked_works() sets the deferred work's state to KSMBD_WORK_CLOSED and wakes the smb2_lock() worker. The worker takes the non-ACTIVE early-exit, locks_free_lock()s the file_lock and, because the state is not KSMBD_WORK_CANCELLED, takes the STATUS_RANGE_NOT_LOCKED branch with "goto out2" -- which, like the cancelled branch, skips release_async_work(). The work stays on conn->async_requests with a live cancel_fn = smb2_remove_blocked_lock pointing at the freed file_lock. A subsequent SMB2_CANCEL for the same AsyncId then passes the KSMBD_WORK_CANCELLED-only guard (its state is KSMBD_WORK_CLOSED), so smb2_cancel() fires cancel_fn again over the freed file_lock -- the same use-after-free fixed, via SMB2_CLOSE instead of a first SMB2_CANCEL: BUG: KASAN: slab-use-after-free in __locks_delete_block __locks_delete_block locks_delete_block ksmbd_vfs_posix_lock_unblock smb2_remove_blocked_lock smb2_cancel <- 2nd SMB2_CANCEL fires cancel_fn handle_ksmbd_work Allocated by ...: locks_alloc_lock <- smb2_lock Freed by ...: locks_free_lock <- smb2_lock (non-ACTIVE early-exit) ... cache file_lock_cache of size 192 Reproduced on mainline 7.1-rc7 (which already contains f580d27e8928) with KASAN by an authenticated SMB client; the double-SMB2_CANCEL control is silent on that kernel, so the splat is attributable to the CLOSE trigger. Only an ACTIVE deferred work may have its cancel_fn fired: both terminal states (CANCELLED and CLOSED) reach the smb2_lock() early-exit that frees the file_lock and skips release_async_work(). Guard on KSMBD_WORK_ACTIVE so any non-active work is skipped.
Quoted source text, attributed separately from HOL analysis.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=b7063c7426ea5a4d15e01b60538718765392f49d <a796ba4e61d5e14e07b79a359faac69f8f9b22a3 || >=0da2e073f9cbf4985a0fd9acb71bc5ff599f8afd <b8e274e69ab09222c7a552c7c0c1eef9ce627fc1 || >=89ae9df09d2c1fb4a4eb495c113a7ce1dca34147 <ddb9239828336b36d8a3ef5943fdffb2f55b6508 || >=14d2eee0193ac3cd1bf3d014373449f0b8d35d6d <94083db751930b1540ddff2b54d4677549c57f81 || >=f580d27e8928828693df44ba2db0fffdbe11dfea <12c36c99655f325befe50c26842f7deca414c381 || >=f580d27e8928828693df44ba2db0fffdbe11dfea <10f293a07f9e10e988b0ae44e2e99c631f5a68e0 || 2b2eda2821cff1d1b5a423b6ee7d8fc6fbc8e694 || >=6.1.176 <6.1.178 || >=6.6.143 <6.6.145 || >=6.12.94 <6.12.96 || >=6.18.36 <6.18.39 || >=7.0.13 <7.1 | a796ba4e61d5e14e07b79a359faac69f8f9b22a3, b8e274e69ab09222c7a552c7c0c1eef9ce627fc1, ddb9239828336b36d8a3ef5943fdffb2f55b6508, 94083db751930b1540ddff2b54d4677549c57f81, 12c36c99655f325befe50c26842f7deca414c381, 10f293a07f9e10e988b0ae44e2e99c631f5a68e0, 6.1.178, 6.6.145, 6.12.96, 6.18.39, 7.1 |
| Linux/Linuxgeneric | 7.1 | Not reported |
Published upstream
Jul 25, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free of a deferred file_lock on SMB2_CLOSE then SMB2_CANCEL Commit f580d27e8928 ("ksmbd: fix use-after-free of a deferred file_lock on double SMB2_CANCEL") made smb2_cancel() skip a work whose state is KSMBD_WORK_CANCELLED, so its cancel_fn cannot be fired a second time. But KSMBD_WORK has three states (ACTIVE, CANCELLED, CLOSED), and the same freeing producer path is reached for CLOSED too: SMB2_CLOSE on the locking handle -> set_close_state_blocked_works() sets the deferred work's state to KSMBD_WORK_CLOSED and wakes the smb2_lock() worker. The worker takes the non-ACTIVE early-exit, locks_free_lock()s the file_lock and, because the state is not KSMBD_WORK_CANCELLED, takes the STATUS_RANGE_NOT_LOCKED branch with "goto out2" -- which, like the cancelled branch, skips release_async_work(). The work stays on conn->async_requests with a live cancel_fn = smb2_remove_blocked_lock pointing at the freed file_lock. A subsequent SMB2_CANCEL for the same AsyncId then passes the KSMBD_WORK_CANCELLED-only guard (its state is KSMBD_WORK_CLOSED), so smb2_cancel() fires cancel_fn again over the freed file_lock -- the same use-after-free fixed, via SMB2_CLOSE instead of a first SMB2_CANCEL: BUG: KASAN: slab-use-after-free in __locks_delete_block __locks_delete_block locks_delete_block ksmbd_vfs_posix_lock_unblock smb2_remove_blocked_lock smb2_cancel <- 2nd SMB2_CANCEL fires cancel_fn handle_ksmbd_work Allocated by ...: locks_alloc_lock <- smb2_lock Freed by ...: locks_free_lock <- smb2_lock (non-ACTIVE early-exit) ... cache file_lock_cache of size 192 Reproduced on mainline 7.1-rc7 (which already contains f580d27e8928) with KASAN by an authenticated SMB client; the double-SMB2_CANCEL control is silent on that kernel, so the splat is attributable to the CLOSE trigger. Only an ACTIVE deferred work may have its cancel_fn fired: both terminal states (CANCELLED and CLOSED) reach the smb2_lock() early-exit that frees the file_lock and skips release_async_work(). Guard on KSMBD_WORK_ACTIVE so any non-active work is skipped.
Quoted source text, attributed separately from HOL analysis.