PT-2026-106502 · Linux · Linux

CVE-2026-98173

·

Published

2026-10-06

·

Updated

2026-10-06

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
smb: client: fix use-after-free of iface in cifs try adding channels()
cifs try adding channels() iterates ses->iface list with list for each entry safe from(), which captures the next entry (niface) under iface lock. The loop body then drops iface lock for the whole duration of cifs ses add channel().
A concurrent interface refresh (SMB3 request interfaces() -> parse server interfaces()) marks all ifaces inactive and removes and frees any that are not re-advertised via list del() + kref put(), where release iface() is a bare kfree(). Since niface typically has no channel holding a reference, the list reference is its last and it can be freed inside the unlocked window. On continue, the iterator advance step then dereferences niface->iface head.next, and the loop body reads iface->rdma capable/is active, both on freed memory.
Fix this by never keeping an unreferenced list pointer across the unlocked window. Each channel attempt now re-scans the list from the head under iface lock, takes a kref on the selected candidate, and passes only that referenced candidate to cifs ses add channel(). weight fulfilled still tracks selection progress, so restarting the scan preserves the original weighted distribution and the weight fulfilled-before-kref put ordering on the failure path.
Add a per-pass attempts cap so a flapping interface refresh cannot keep the inner loop spinning within a single tries increment.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-98173

Affected Products

Linux