PT-2026-106502 · Linux · Linux
CVE-2026-98173
·
Publicado
2026-10-06
·
Atualizado
2026-10-06
Nenhuma
Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
smb: client: fix use-after-free of iface in cifs try adding channels()
cifs try adding channels() iterates ses->iface list with
list for each entry safe from(), which captures the next entry
(niface) under iface lock. The loop body then drops iface lock for
the whole duration of cifs ses add channel().
A concurrent interface refresh (SMB3 request interfaces() ->
parse server interfaces()) marks all ifaces inactive and removes and
frees any that are not re-advertised via list del() + kref put(),
where release iface() is a bare kfree(). Since niface typically has
no channel holding a reference, the list reference is its last and it
can be freed inside the unlocked window. On continue, the iterator
advance step then dereferences niface->iface head.next, and the loop
body reads iface->rdma capable/is active, both on freed memory.
Fix this by never keeping an unreferenced list pointer across the
unlocked window. Each channel attempt now re-scans the list from the
head under iface lock, takes a kref on the selected candidate, and
passes only that referenced candidate to cifs ses add channel().
weight fulfilled still tracks selection progress, so restarting the
scan preserves the original weighted distribution and the
weight fulfilled-before-kref put ordering on the failure path.
Add a per-pass attempts cap so a flapping interface refresh cannot
keep the inner loop spinning within a single tries increment.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Linux