CVE-2026-98174 PUBLISHED

smb: client: fix rlist race and missing initialization

Assigner: Linux
Reserved: 25.09.2026 Published: 06.10.2026 Updated: 06.10.2026

In the Linux kernel, the following vulnerability has been resolved:

smb: client: fix rlist race and missing initialization

TCP_Server_Info.rlist is allocated via kzalloc which zeros both ->next and ->prev to NULL instead of pointing to itself, making list_empty() always return false and list_add() dereference a NULL ->prev pointer.

Also, cifs_signal_cifsd_for_reconnect() can be called concurrently from multiple cifsd threads, allowing the same server's rlist node to be added twice into the local list, corrupting it.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 to b5f924ffbfa976e4b97f17e8132c595b97482c2d (excl.)
  • affected from 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 to 5a8f82f9c5839389cf4036029dd75a9911049e83 (excl.)
  • affected from 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 to 04082b1833856cb9ed87e0d3d5f04cbf836cf7da (excl.)
  • affected from 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 to c037d6bde3dd5fa00b017b6b98a5389ec0ebc02f (excl.)
  • affected from 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 to 5f270f091256da1338c3631083e15d7f83cc05e1 (excl.)
  • affected from 0 to 6.6.158 (excl.)
  • affected from 0 to 6.12.112 (excl.)
  • affected from 0 to 6.18.54 (excl.)
  • affected from 0 to 7.2.8 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • unaffected from 6.6.158 to 6.6.* (incl.)
  • unaffected from 6.12.112 to 6.12.* (incl.)
  • unaffected from 6.18.54 to 6.18.* (incl.)
  • unaffected from 7.2.8 to 7.2.* (incl.)
  • unaffected from 7.3-rc4 to * (incl.)

References