๐Ÿ” CVE Alert

CVE-2026-98175

UNKNOWN 0.0

smb: client: cancel reconnect work in clean_demultiplex_info()

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: smb: client: cancel reconnect work in clean_demultiplex_info() clean_demultiplex_info() cancels server->echo delayed work but not server->reconnect, which can cause a use-after-free when the demultiplex thread exits while a reconnect work is still queued: cifs_demultiplex_thread() cifs_readv_from_socket() cifs_reconnect() __cifs_reconnect() cifs_queue_server_reconn() mod_delayed_work(cifsiod_wq, &server->reconnect, 0) clean_demultiplex_info() cancel_delayed_work_sync(&server->echo) // echo canceled // reconnect NOT canceled kfree_sensitive(server) // server freed ...later, on cifsiod_wq: smb2_reconnect_server() server->srv_count // UAF read of freed server Fix this by canceling server->reconnect delayed work in clean_demultiplex_info() before the server is freed, the same way cifs_put_tcp_session() already does.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Oct 6, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
53e0e11efe9289535b060a51d4cf37c25e0d0f2b < 180380272f116dbd2b0354c5c7872e112e519149 53e0e11efe9289535b060a51d4cf37c25e0d0f2b < e3f6a779433d13aafb5edab59e4f9313051e8a52 53e0e11efe9289535b060a51d4cf37c25e0d0f2b < 7ab9ceedd860216fb97f2d8574cbe58b8906f42a 53e0e11efe9289535b060a51d4cf37c25e0d0f2b < 2e5103e11a17c274715dd56cf185eeedccf686b8 53e0e11efe9289535b060a51d4cf37c25e0d0f2b < c65eae6f61d1778ff7a82e4aae4080e26f486af1 e008a962311a875a828cbae54b43285858aaa6c8 123b228a09b90b50b0a9d6eb8294cf0c42efc029 0ba4c6eaaacbcc4b18f51bb3b1567c65a8fecca9 d0d2a4c82942e2f51e4984beea1f7e5a994bd06c 15a12fbbf365a483b1c19f9caeb707b3bea77e10 f0b715409cb9cf7e21e690f9b163047739761962 ff04da387c10b6bf7b510392742c8cd46c130fd6 48f9526f4dcb4b132fe0dc2450835311e3b013a6 3.10.107 < 3.11 3.12.70 < 3.13 3.16.42 < 3.17 3.18.47 < 3.19 4.1.38 < 4.2 4.4.40 < 4.5 4.8.16 < 4.9 4.9.1 < 4.10
Linux / Linux
4.10

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/180380272f116dbd2b0354c5c7872e112e519149 git.kernel.org: https://git.kernel.org/stable/c/e3f6a779433d13aafb5edab59e4f9313051e8a52 git.kernel.org: https://git.kernel.org/stable/c/7ab9ceedd860216fb97f2d8574cbe58b8906f42a git.kernel.org: https://git.kernel.org/stable/c/2e5103e11a17c274715dd56cf185eeedccf686b8 git.kernel.org: https://git.kernel.org/stable/c/c65eae6f61d1778ff7a82e4aae4080e26f486af1