CVE-2026-64136 PUBLISHED

smb: client: protect tc_count increment in smb2_find_smb_sess_tcon_unlocked()

Assigner: Linux
Reserved: 19.07.2026 Published: 19.07.2026 Updated: 20.07.2026

In the Linux kernel, the following vulnerability has been resolved:

smb: client: protect tc_count increment in smb2_find_smb_sess_tcon_unlocked()

Commit 96c4af418586 ("cifs: Fix locking usage for tcon fields") refactored cifs code to change cifs_tcp_ses_lock for tc_lock around tc_count changes.

There was missing lock around tc_count increment inside smb2_find_smb_sess_tcon_unlocked().

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 9.8

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 953953abb66e52c224057ab91e404284fefeab62 to 7df1df6f40c0720d30206aa35c0343b962350e0d (excl.)
  • affected from 601dd3b79769b38d30b693c40afdb2a4b7edf9d0 to 13fb413ae22a37c69341918a6d651d19a9b0b9b7 (excl.)
  • affected from 3969db6b22e3d90d8c5f22ac1a7fe0350a94c136 to bf4ebdb19ff9b3cdf992b50715fe61633327416a (excl.)
  • affected from 96c4af418586ee9a6aab61738644366426e05316 to e374f4e496fef8168784f93a4477d67be34485fd (excl.)
  • affected from 96c4af418586ee9a6aab61738644366426e05316 to 4d8690dace005a38e6dbde9ecce2da3ad85c7c41 (excl.)
  • Version 8c59eeeeffa1524ef57e173a89a1a3ff539888d5 is affected
  • affected from 6.6.128 to 6.6.142 (excl.)
  • affected from 6.12.75 to 6.12.92 (excl.)
  • affected from 6.18.16 to 6.18.34 (excl.)
  • affected from 6.19.6 to 6.20 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 7.0 is affected
  • unaffected from 0 to 7.0 (excl.)
  • unaffected from 6.6.142 to 6.6.* (incl.)
  • unaffected from 6.12.92 to 6.12.* (incl.)
  • unaffected from 6.18.34 to 6.18.* (incl.)
  • unaffected from 7.0.11 to 7.0.* (incl.)
  • unaffected from 7.1 to * (incl.)

References