SB2026091939 - Improper locking in Linux kernel smb server
Published: September 19, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper locking (CVE-ID: CVE-2026-90176)
CWE-ID: CWE-667 - Improper Locking
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass byte-range lock restrictions.
The vulnerability exists due to improper lock checking in the ksmbd check_lock_range() function when handling one-byte read, write, copychunk, or truncate operations. A remote attacker can issue a one-byte operation that conflicts with an existing byte-range lock to bypass byte-range lock restrictions.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/07a9e289ff7edcc004f58952405f8a65c4e37512
- https://git.kernel.org/stable/c/84c2d8e807ac489f5c91769293fb15dfdae8bae8
- https://git.kernel.org/stable/c/993e0158331d37c04da18efe551b5e1e35fb3078
- https://git.kernel.org/stable/c/a89cc145832e81c32199d4ca2e1ea8bd51ed601d
- https://git.kernel.org/stable/c/d40c24634fe077a0dc91fd11fccf44ce12b454d5
- https://git.kernel.org/stable/c/f751d6e39d4c937c45f8fedc66699aa7d2d52288