Improper locking in Linux kernel - CVE-2026-90176
Published: September 19, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass byte-range lock restrictions.
The vulnerability exists due to improper lock checking in the ksmbd check_lock_range() function when handling one-byte read, write, copychunk, or truncate operations. A remote attacker can issue a one-byte operation that conflicts with an existing byte-range lock to bypass byte-range lock restrictions.
Affected software
How to mitigate CVE-2026-90176
External References
- https://git.kernel.org/stable/c/07a9e289ff7edcc004f58952405f8a65c4e37512
- https://git.kernel.org/stable/c/84c2d8e807ac489f5c91769293fb15dfdae8bae8
- https://git.kernel.org/stable/c/993e0158331d37c04da18efe551b5e1e35fb3078
- https://git.kernel.org/stable/c/a89cc145832e81c32199d4ca2e1ea8bd51ed601d
- https://git.kernel.org/stable/c/d40c24634fe077a0dc91fd11fccf44ce12b454d5
- https://git.kernel.org/stable/c/f751d6e39d4c937c45f8fedc66699aa7d2d52288