{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.19.11-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  ksmbd: fix use-after-free and NULL deref in smb_grant_oplock()  smb_grant_oplock() has two issues in the oplock publication sequence:  1) opinfo is linked into ci-\u003em_op_list (via opinfo_add) before    add_lease_global_list() is called.  If add_lease_global_list()    fails (kmalloc returns NULL), the error path frees the opinfo    via __free_opinfo() while it is still linked in ci-\u003em_op_list.    Concurrent m_op_list readers (opinfo_get_list, or direct iteration    in smb_break_all_levII_oplock) dereference the freed node.  2) opinfo-\u003eo_fp is assigned after add_lease_global_list() publishes    the opinfo on the global lease list.  A concurrent    find_same_lease_key() can walk the lease list and dereference    opinfo-\u003eo_fp-\u003ef_ci while o_fp is still NULL.  Fix by restructuring the publication sequence to eliminate post-publish failure:  - Set opinfo-\u003eo_fp before any list publication (fixes NULL deref). - Preallocate lease_table via alloc_lease_table() before opinfo_add()   so add_lease_global_list() becomes infallible after publication. - Keep the original m_op_list publication order (opinfo_add before   lease list) so concurrent opens via same_client_has_lease() and   opinfo_get_list() still see the in-flight grant. - Use opinfo_put() instead of __free_opinfo() on err_out so that   the RCU-deferred free path is used.  This also requires splitting add_lease_global_list() to take a preallocated lease_table and changing its return type from int to void, since it can no longer fail.",
  "id": "DEBIAN-CVE-2026-31444",
  "modified": "2026-09-14T16:47:47.740244930Z",
  "published": "2026-04-22T14:16:38.010Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-31444"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ],
  "upstream": [
    "CVE-2026-31444"
  ]
}