PT-2026-106501 · Linux · Linux

CVE-2026-98172

·

Published

2026-10-06

·

Updated

2026-10-06

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
smb: client: fix smbd connection leak on cifs get tcp session() error
When an RDMA connection is successfully established via smbd get connection() but cifs get tcp session() later fails (e.g. kthread create() returns an error), the error path frees tcp ses without first destroying the smbd connection.
Fix this by calling smbd destroy() in the out err cleanup path before kfree(tcp ses). smbd destroy() safely handles the case where smbd conn is NULL, so it can be called unconditionally.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-98172

Affected Products

Linux