PT-2026-106590 · Linux · Linux
CVE-2026-98261
·
Published
2026-10-06
·
Updated
2026-10-06
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
cifs: Fix server use-after-free in cifs chan skip or disable()
When a secondary channel is no longer supported by the server,
cifs chan skip or disable() drops the channel reference with
cifs put tcp session() and then continues to use the server pointer by
calling cifs signal cifsd for reconnect() on it and reading its
primary server pointer. cifs put tcp session() can drop the last
reference of the channel and tear it down, so both the channel and the
primary server (whose reference is also dropped by
cifs put tcp session()) can be freed before they are signaled for
reconnect.
Signal the channel and the primary server and capture the primary
server pointer before dropping the channel reference with
cifs put tcp session().
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux