cifs: Fix server use-after-free in cifs_chan_skip_or_disable()
Summary
| CVE | CVE-2026-98261 |
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-10-06 09:18:15 UTC |
| Updated | 2026-10-06 09:18:15 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved:
cifs: Fix server use-after-free in cifs_chan_skip_or_disable()
When a secondary channel is no longer supported by the server,
cifs_chan_skip_or_disable() drops the channel reference with
cifs_put_tcp_session() and then continues to use the server pointer by
calling cifs_signal_cifsd_for_reconnect() on it and reading its
primary_server pointer. cifs_put_tcp_session() can drop the last
reference of the channel and tear it down, so both the channel and the
primary server (whose reference is also dropped by
cifs_put_tcp_session()) can be freed before they are signaled for
reconnect.
Signal the channel and the primary server and capture the primary
server pointer before dropping the channel reference with
cifs_put_tcp_session(). |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|
| CNA |
Linux |
Linux |
affected 50e8363ecc85da49764781da90ebffe1a657b370 0338489960ddad6368bce55e8adbc176c523093d git |
Not specified |
| CNA |
Linux |
Linux |
affected f591062bdbf4742b7f1622173017f19e927057b0 edd52eae5fcfb8433b6bb0e7cd98db438fe01227 git |
Not specified |
| CNA |
Linux |
Linux |
affected f591062bdbf4742b7f1622173017f19e927057b0 fcc0a935bb6e37ecbf7e4335061309f896f35780 git |
Not specified |
| CNA |
Linux |
Linux |
affected f591062bdbf4742b7f1622173017f19e927057b0 7a1b27780b113583a94256d58dabfe7c0d9286e7 git |
Not specified |
| CNA |
Linux |
Linux |
affected f591062bdbf4742b7f1622173017f19e927057b0 717e0a25036b6c92cecace30913b2d874a4c22b8 git |
Not specified |
| CNA |
Linux |
Linux |
affected d61ba1d71ea6039eca7ada870bf3f0c3c8fc12e4 git |
Not specified |
| CNA |
Linux |
Linux |
affected 6.6.15 6.6.158 semver |
Not specified |
| CNA |
Linux |
Linux |
affected 6.7.3 6.8 semver |
Not specified |
| CNA |
Linux |
Linux |
affected 6.8 |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.8 semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.6.158 6.6.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.12.112 6.12.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.18.54 6.18.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.2.8 7.2.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.3-rc4 * original_commit_for_fix |
Not specified |
References
| Reference | Source | Link | Tags |
|---|
| git.kernel.org/stable/c/fcc0a935bb6e37ecbf7e4335061309f896f35780 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/717e0a25036b6c92cecace30913b2d874a4c22b8 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/0338489960ddad6368bce55e8adbc176c523093d |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/edd52eae5fcfb8433b6bb0e7cd98db438fe01227 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/7a1b27780b113583a94256d58dabfe7c0d9286e7 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.