{"id":"CVE-2026-90156","published":"2026-09-17T17:17:08.717","lastModified":"2026-09-18T18:17:44.593","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: safely discard unregistered deferred locks\n\nWhen vfs_lock_file() defers a lock, smb2_lock() puts its ksmbd_lock on\nrollback_list before allocating and registering the asynchronous work.\nIf either operation fails, rollback assumes that smb_lock->conn is\ninitialized and dereferences NULL. The deferred file_lock also remains\nlinked into the VFS blocked-lock state while it is freed.\n\nKeep the lock off rollback_list until async setup succeeds. On setup\nfailures, explicitly unblock and wake the deferred lock before freeing it\nand its ksmbd wrapper.","cvssScore":null,"cvssSeverity":null,"cvssVector":null,"cwes":[],"vendors":[],"products":[],"references":[{"url":"https://git.kernel.org/stable/c/054bcca4cd9f00719b01f7108b51a2168fb94f15","tags":[]},{"url":"https://git.kernel.org/stable/c/d09af9a35ff7b77a950b507133d9092aadbfeff4","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}