CVE-2026-64397 PUBLISHED

ksmbd: serialize QUERY_DIRECTORY requests per file

Assigner: Linux
Reserved: 19.07.2026 Published: 25.07.2026 Updated: 25.07.2026

In the Linux kernel, the following vulnerability has been resolved:

ksmbd: serialize QUERY_DIRECTORY requests per file

smb2_query_dir() stores a pointer to its stack-allocated private data in the ksmbd_file readdir_data. Concurrent QUERY_DIRECTORY requests using the same file handle can overwrite this pointer while an iterate_dir() callback is still using it, resulting in a stack use-after-free.

Add a per-file mutex and hold it while accessing the shared directory enumeration state. The lock covers scan restart, dot entry state, readdir_data setup and iteration, and response construction. This prevents another request from replacing readdir_data.private before the current request has finished using it and also serializes the shared file position.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 to 1426fd79102539bc0ab5c8fced047ad4313b9908 (excl.)
  • affected from 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 to 2a64dbf9c739ddf7a25a066507597bf89f8f73d2 (excl.)
  • affected from 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 to 64dac2d486ec1eb18dc00968b16a230b6b75ec24 (excl.)
  • affected from 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 to a1d5d31cad593ea5e1b637f2f39c9ef6d09d1199 (excl.)
  • affected from 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 to fd22b039a5a05bc1d6818e9dcd1001fb432a829d (excl.)
  • affected from 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 to be6d26bf27499977c746abc163659915082348d8 (excl.)
  • affected from 0 to 6.1.178 (excl.)
  • affected from 0 to 6.6.145 (excl.)
  • affected from 0 to 6.12.96 (excl.)
  • affected from 0 to 6.18.39 (excl.)
  • affected from 0 to 7.1.4 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • unaffected from 6.1.178 to 6.1.* (incl.)
  • unaffected from 6.6.145 to 6.6.* (incl.)
  • unaffected from 6.12.96 to 6.12.* (incl.)
  • unaffected from 6.18.39 to 6.18.* (incl.)
  • unaffected from 7.1.4 to 7.1.* (incl.)
  • unaffected from 7.2-rc1 to * (incl.)

References