๐Ÿ” CVE Alert

CVE-2026-98173

UNKNOWN 0.0

smb: client: fix use-after-free of iface in cifs_try_adding_channels()

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix use-after-free of iface in cifs_try_adding_channels() cifs_try_adding_channels() iterates ses->iface_list with list_for_each_entry_safe_from(), which captures the next entry (niface) under iface_lock. The loop body then drops iface_lock for the whole duration of cifs_ses_add_channel(). A concurrent interface refresh (SMB3_request_interfaces() -> parse_server_interfaces()) marks all ifaces inactive and removes and frees any that are not re-advertised via list_del() + kref_put(), where release_iface() is a bare kfree(). Since niface typically has no channel holding a reference, the list reference is its last and it can be freed inside the unlocked window. On continue, the iterator advance step then dereferences niface->iface_head.next, and the loop body reads iface->rdma_capable/is_active, both on freed memory. Fix this by never keeping an unreferenced list pointer across the unlocked window. Each channel attempt now re-scans the list from the head under iface_lock, takes a kref on the selected candidate, and passes only that referenced candidate to cifs_ses_add_channel(). weight_fulfilled still tracks selection progress, so restarting the scan preserves the original weighted distribution and the weight_fulfilled-before-kref_put ordering on the failure path. Add a per-pass attempts cap so a flapping interface refresh cannot keep the inner loop spinning within a single tries increment.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Oct 6, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
aa45dadd34e44fcd6a9df4b395bee5b5633b4cec < c941f1ebfd26f683de81091473f3596a218abff0 aa45dadd34e44fcd6a9df4b395bee5b5633b4cec < e99040e5e9c60441e6b4725e1a7b88c3106ae903 aa45dadd34e44fcd6a9df4b395bee5b5633b4cec < ec36b38e65596950e6c29bed7dfc90b98707c19c aa45dadd34e44fcd6a9df4b395bee5b5633b4cec < d034e836eefd7ce75e588f7031cffbeec594f5ac
Linux / Linux
5.19

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/c941f1ebfd26f683de81091473f3596a218abff0 git.kernel.org: https://git.kernel.org/stable/c/e99040e5e9c60441e6b4725e1a7b88c3106ae903 git.kernel.org: https://git.kernel.org/stable/c/ec36b38e65596950e6c29bed7dfc90b98707c19c git.kernel.org: https://git.kernel.org/stable/c/d034e836eefd7ce75e588f7031cffbeec594f5ac