PT-2026-106590 · Linux · Linux

CVE-2026-98261

·

Published

2026-10-06

·

Updated

2026-10-06

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
cifs: Fix server use-after-free in cifs chan skip or disable()
When a secondary channel is no longer supported by the server, cifs chan skip or disable() drops the channel reference with cifs put tcp session() and then continues to use the server pointer by calling cifs signal cifsd for reconnect() on it and reading its primary server pointer. cifs put tcp session() can drop the last reference of the channel and tear it down, so both the channel and the primary server (whose reference is also dropped by cifs put tcp session()) can be freed before they are signaled for reconnect.
Signal the channel and the primary server and capture the primary server pointer before dropping the channel reference with cifs put tcp session().
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-98261

Affected Products

Linux