CVE-2026-98261 PUBLISHED

cifs: Fix server use-after-free in cifs_chan_skip_or_disable()

Assigner: Linux
Reserved: 25.09.2026 Published: 06.10.2026 Updated: 06.10.2026

In the Linux kernel, the following vulnerability has been resolved:

cifs: Fix server use-after-free in cifs_chan_skip_or_disable()

When a secondary channel is no longer supported by the server, cifs_chan_skip_or_disable() drops the channel reference with cifs_put_tcp_session() and then continues to use the server pointer by calling cifs_signal_cifsd_for_reconnect() on it and reading its primary_server pointer. cifs_put_tcp_session() can drop the last reference of the channel and tear it down, so both the channel and the primary server (whose reference is also dropped by cifs_put_tcp_session()) can be freed before they are signaled for reconnect.

Signal the channel and the primary server and capture the primary server pointer before dropping the channel reference with cifs_put_tcp_session().

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 50e8363ecc85da49764781da90ebffe1a657b370 to 0338489960ddad6368bce55e8adbc176c523093d (excl.)
  • affected from f591062bdbf4742b7f1622173017f19e927057b0 to edd52eae5fcfb8433b6bb0e7cd98db438fe01227 (excl.)
  • affected from f591062bdbf4742b7f1622173017f19e927057b0 to fcc0a935bb6e37ecbf7e4335061309f896f35780 (excl.)
  • affected from f591062bdbf4742b7f1622173017f19e927057b0 to 7a1b27780b113583a94256d58dabfe7c0d9286e7 (excl.)
  • affected from f591062bdbf4742b7f1622173017f19e927057b0 to 717e0a25036b6c92cecace30913b2d874a4c22b8 (excl.)
  • Version d61ba1d71ea6039eca7ada870bf3f0c3c8fc12e4 is affected
  • affected from 6.6.15 to 6.6.158 (excl.)
  • affected from 6.7.3 to 6.8 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 6.8 is affected
  • unaffected from 0 to 6.8 (excl.)
  • unaffected from 6.6.158 to 6.6.* (incl.)
  • unaffected from 6.12.112 to 6.12.* (incl.)
  • unaffected from 6.18.54 to 6.18.* (incl.)
  • unaffected from 7.2.8 to 7.2.* (incl.)
  • unaffected from 7.3-rc4 to * (incl.)

References