{
  "affected": [
    {
      "ranges": [
        {
          "events": [
            {
              "introduced": "e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9"
            },
            {
              "fixed": "5f97bac88bfb333f426f01c118b8235e75af8d96"
            },
            {
              "fixed": "b0148dc5625dbfd50596ac63c7487c12e8a8ab03"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        }
      ]
    },
    {
      "package": {
        "ecosystem": "Linux",
        "name": "Kernel"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "5.15.0"
            },
            {
              "fixed": "7.2.6"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "database_specific": {
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/90xxx/CVE-2026-90167.json"
  },
  "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: serialize oplock close with pending break ownership\n\nclose may abort an in-flight oplock break while another breaker already\nholds an opinfo reference. Releasing pending_break wakes that waiter, but\nwithout serializing the close transition with bit acquisition it can become\na new break owner through the test_and_set_bit() fast path. It can then\noverwrite OPLOCK_CLOSING with OPLOCK_ACK_WAIT and continue a break for\na dying opinfo.\n\nMake OPLOCK_CLOSING terminal once the opinfo is removed from the inode\nlist. Serialize that transition, pending_break acquisition, and\nOPLOCK_ACK_WAIT setup with an opinfo state lock. A breaker which loses\nthe race releases its ownership and returns -ENOENT. Explicitly wake\npending_break waiters during close so they can observe the terminal state.\n\nAlso prevent ACK and timeout paths from replacing OPLOCK_CLOSING with\nOPLOCK_STATE_NONE.",
  "id": "CVE-2026-90167",
  "modified": "2026-09-19T03:31:02.497374643Z",
  "published": "2026-09-17T16:06:56.507Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/5f97bac88bfb333f426f01c118b8235e75af8d96"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/b0148dc5625dbfd50596ac63c7487c12e8a8ab03"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/90xxx/CVE-2026-90167.json"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90167"
    },
    {
      "type": "PACKAGE",
      "url": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"
    }
  ],
  "schema_version": "1.9.0",
  "summary": "ksmbd: serialize oplock close with pending break ownership"
}