Use-after-free in Linux kernel - CVE-2026-90155
Published: September 19, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to use-after-free in ksmbd byte-range lock handling when processing SMB byte-range lock requests with blocked dependent waiters. A remote attacker can submit lock requests that leave a dependent waiter attached to a freed lock to cause a denial of service.