CVE-2026-98175
N/A
Summary
In the Linux kernel, the following vulnerability has been resolved:
smb: client: cancel reconnect work in clean_demultiplex_info()
clean_demultiplex_info() cancels server->echo delayed work but not server->reconnect, which can cause a use-after-free when the demultiplex thread exits while a reconnect work is still queued:
cifs_demultiplex_thread() cifs_readv_from_socket() cifs_reconnect() __cifs_reconnect() cifs_queue_server_reconn() mod_delayed_work(cifsiod_wq, &server->reconnect, 0) clean_demultiplex_info() cancel_delayed_work_sync(&server->echo) // echo canceled // reconnect NOT canceled kfree_sensitive(server) // server freed
…later, on cifsiod_wq:
smb2_reconnect_server() server->srv_count // UAF read of freed server
Fix this by canceling server->reconnect delayed work in clean_demultiplex_info() before the server is freed, the same way cifs_put_tcp_session() already does.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 53e0e11efe9289535b060a51d4cf37c25e0d0f2b < 180380272f116dbd2b0354c5c7872e112e519149 | affected |
| Linux | Linux | 53e0e11efe9289535b060a51d4cf37c25e0d0f2b < e3f6a779433d13aafb5edab59e4f9313051e8a52 | affected |
| Linux | Linux | 53e0e11efe9289535b060a51d4cf37c25e0d0f2b < 7ab9ceedd860216fb97f2d8574cbe58b8906f42a | affected |
| Linux | Linux | 53e0e11efe9289535b060a51d4cf37c25e0d0f2b < 2e5103e11a17c274715dd56cf185eeedccf686b8 | affected |
| Linux | Linux | 53e0e11efe9289535b060a51d4cf37c25e0d0f2b < c65eae6f61d1778ff7a82e4aae4080e26f486af1 | affected |
| Linux | Linux | e008a962311a875a828cbae54b43285858aaa6c8 | affected |
| Linux | Linux | 123b228a09b90b50b0a9d6eb8294cf0c42efc029 | affected |
| Linux | Linux | 0ba4c6eaaacbcc4b18f51bb3b1567c65a8fecca9 | affected |
| Linux | Linux | d0d2a4c82942e2f51e4984beea1f7e5a994bd06c | affected |
| Linux | Linux | 15a12fbbf365a483b1c19f9caeb707b3bea77e10 | affected |
| Linux | Linux | f0b715409cb9cf7e21e690f9b163047739761962 | affected |
| Linux | Linux | ff04da387c10b6bf7b510392742c8cd46c130fd6 | affected |
| Linux | Linux | 48f9526f4dcb4b132fe0dc2450835311e3b013a6 | affected |
| Linux | Linux | 3.10.107 < 3.11 | affected |
| Linux | Linux | 3.12.70 < 3.13 | affected |
| Linux | Linux | 3.16.42 < 3.17 | affected |
| Linux | Linux | 3.18.47 < 3.19 | affected |
| Linux | Linux | 4.1.38 < 4.2 | affected |
| Linux | Linux | 4.4.40 < 4.5 | affected |
| Linux | Linux | 4.8.16 < 4.9 | affected |
| Linux | Linux | 4.9.1 < 4.10 | affected |
| Linux | Linux | 4.10 | affected |
| Linux | Linux | 0 < 4.10 | unaffected |
| Linux | Linux | 6.6.158 <= 6.6.* | unaffected |
| Linux | Linux | 6.12.112 <= 6.12.* | unaffected |
| Linux | Linux | 6.18.54 <= 6.18.* | unaffected |
| Linux | Linux | 7.2.8 <= 7.2.* | unaffected |
| Linux | Linux | 7.3-rc4 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/180380272f116dbd2b0354c5c7872e112e519149
- https://git.kernel.org/stable/c/e3f6a779433d13aafb5edab59e4f9313051e8a52
- https://git.kernel.org/stable/c/7ab9ceedd860216fb97f2d8574cbe58b8906f42a
- https://git.kernel.org/stable/c/2e5103e11a17c274715dd56cf185eeedccf686b8
- https://git.kernel.org/stable/c/c65eae6f61d1778ff7a82e4aae4080e26f486af1
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.