smb: client: protect tc_count increment in smb2_find_smb_sess_tcon_unlocked()
Summary
| CVE | CVE-2026-64136 |
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-07-19 16:17:55 UTC |
| Updated | 2026-07-19 16:17:55 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved:
smb: client: protect tc_count increment in smb2_find_smb_sess_tcon_unlocked()
Commit 96c4af418586 ("cifs: Fix locking usage for tcon fields")
refactored cifs code to change cifs_tcp_ses_lock for tc_lock around
tc_count changes.
There was missing lock around tc_count increment inside
smb2_find_smb_sess_tcon_unlocked(). |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|
| CNA |
Linux |
Linux |
affected 953953abb66e52c224057ab91e404284fefeab62 7df1df6f40c0720d30206aa35c0343b962350e0d git |
Not specified |
| CNA |
Linux |
Linux |
affected 601dd3b79769b38d30b693c40afdb2a4b7edf9d0 13fb413ae22a37c69341918a6d651d19a9b0b9b7 git |
Not specified |
| CNA |
Linux |
Linux |
affected 3969db6b22e3d90d8c5f22ac1a7fe0350a94c136 bf4ebdb19ff9b3cdf992b50715fe61633327416a git |
Not specified |
| CNA |
Linux |
Linux |
affected 96c4af418586ee9a6aab61738644366426e05316 e374f4e496fef8168784f93a4477d67be34485fd git |
Not specified |
| CNA |
Linux |
Linux |
affected 96c4af418586ee9a6aab61738644366426e05316 4d8690dace005a38e6dbde9ecce2da3ad85c7c41 git |
Not specified |
| CNA |
Linux |
Linux |
affected 8c59eeeeffa1524ef57e173a89a1a3ff539888d5 git |
Not specified |
| CNA |
Linux |
Linux |
affected 6.6.128 6.6.142 semver |
Not specified |
| CNA |
Linux |
Linux |
affected 6.12.75 6.12.92 semver |
Not specified |
| CNA |
Linux |
Linux |
affected 6.18.16 6.18.34 semver |
Not specified |
| CNA |
Linux |
Linux |
affected 6.19.6 6.20 semver |
Not specified |
| CNA |
Linux |
Linux |
affected 7.0 |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.0 semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.6.142 6.6.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.12.92 6.12.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.18.34 6.18.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.0.11 7.0.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.1 * original_commit_for_fix |
Not specified |
References
| Reference | Source | Link | Tags |
|---|
| git.kernel.org/stable/c/4d8690dace005a38e6dbde9ecce2da3ad85c7c41 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/e374f4e496fef8168784f93a4477d67be34485fd |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/7df1df6f40c0720d30206aa35c0343b962350e0d |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/bf4ebdb19ff9b3cdf992b50715fe61633327416a |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/13fb413ae22a37c69341918a6d651d19a9b0b9b7 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.