CVE-2026-98112
7.8
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Summary
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: fix listener task lifetime on netdev events
The listener thread exits when its listening socket is shutdown. The netdevice notifier shuts down the socket before calling kthread_stop(), so the task_struct can be freed before kthread_stop() gets its reference.
Create the listener in a stopped state and hold an extra task_struct reference until kthread_stop_put() completes. Also stop and release listeners before freeing their interface records during TCP teardown.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 3316a8fc840d82fad5efcf76ad0ea3f76fdca209 < 40581f10c1e56238b157af5f260b8f9518a0cbc1 | affected |
| Linux | Linux | 3316a8fc840d82fad5efcf76ad0ea3f76fdca209 < a506290f59e1c6ce9ac0a13158640bb8fee93471 | affected |
| Linux | Linux | 6.19 | affected |
| Linux | Linux | 0 < 6.19 | unaffected |
| Linux | Linux | 7.2.7 <= 7.2.* | unaffected |
| Linux | Linux | 7.3-rc2 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/40581f10c1e56238b157af5f260b8f9518a0cbc1
- https://git.kernel.org/stable/c/a506290f59e1c6ce9ac0a13158640bb8fee93471
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.