8.4
CVE-2026-74259
- EPSS 0.18%
- Veröffentlicht 15.08.2026 05:57:36
- Zuletzt bearbeitet 17.08.2026 06:19:19
- CVE-Watchlists
- Unerledigt
cifs: remove all cifs files before kill super
In the Linux kernel, the following vulnerability has been resolved:
cifs: remove all cifs files before kill super
Cifs files may be put into fileinfo_put_wq during umounting cifs.
After umount done, cifsFileInfo_put_final is called, which cause
following BUG:
BUG: kernel NULL pointer dereference, address: 0000000000000000
...
[ 134.222152] list_lru_add+0x64/0x1a0
[ 134.222399] ? cifs_put_tcon+0x171/0x340 [cifs]
[ 134.222772] d_lru_add+0x44/0x60
[ 134.222997] dput+0x1fc/0x210
[ 134.223213] cifsFileInfo_put_final+0x11a/0x140 [cifs]
[ 134.223576] process_one_work+0x17c/0x320
[ 134.223843] worker_thread+0x188/0x280
[ 134.224084] ? __pfx_worker_thread+0x10/0x10
[ 134.224366] kthread+0xcc/0x100
[ 134.224576] ? __pfx_kthread+0x10/0x10
[ 134.224827] ret_from_fork+0x30/0x50
[ 134.225063] ? __pfx_kthread+0x10/0x10
[ 134.225328] ret_from_fork_asm+0x1b/0x30
This can be reproduce by following:
unshare -n bash -c "
mkdir -p ${CIFS_MNT}
ip netns attach root 1
ip link add eth0 type veth peer veth0 netns root
ip link set eth0 up
ip -n root link set veth0 up
ip addr add 192.168.0.2/24 dev eth0
ip -n root addr add 192.168.0.1/24 dev veth0
ip route add default via 192.168.0.1 dev eth0
ip netns exec root sysctl net.ipv4.ip_forward=1
ip netns exec root iptables -t nat -A POSTROUTING -s 192.168.0.2 -o
${DEV} -j MASQUERADE
mount -t cifs ${CIFS_PATH} ${CIFS_MNT} -o
vers=3.0,sec=ntlmssp,credentials=${CIFS_CRED},rsize=65536,wsize=65536,cache=none,echo_interval=1
touch ${CIFS_MNT}/a.txt
ip netns exec root iptables -t nat -D POSTROUTING -s 192.168.0.2 -o
${DEV} -j MASQUERADE
"
umount ${CIFS_MNT}Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
708c276f516d27beaded7f372ac8111cee43926c
Version <
55fb9581986141659002264fdc75cef307811eb8
Status
affected
Version
0629a1a187e424373364d681b42b101894bdb548
Version <
4465ebe67d89345954bb3622b25dd13e06f9d367
Status
affected
Version
0e4b8faaaebe3137bec5723ef2b3cb0437fb38fd
Version <
3baedc9b2f53e6a6ac57b16fdff0f9b954d9ca71
Status
affected
Version
f655467a9973f964b267871e5fef533ad5014494
Version <
21303c4a2b7275e626c6b67de0f45f2d5b9bb3e7
Status
affected
Version
340cea84f691c5206561bb2e0147158fe02070be
Version <
7839f1817a0cb6c4ed5cfe25d04845c43380a129
Status
affected
Version
340cea84f691c5206561bb2e0147158fe02070be
Version <
6d9a4aaaa8b2612b5ef9d581e2f286a458b71ee1
Status
affected
Version
30afc6ea72cc6cf7c8d579e79b64232801c38d08
Status
affected
Version
6.1.167
Version <
6.1.178
Status
affected
Version
6.6.130
Version <
6.6.145
Status
affected
Version
6.12.78
Version <
6.12.97
Status
affected
Version
6.18.20
Version <
6.18.40
Status
affected
Version
6.19.10
Version <
6.20
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
7.0
Status
affected
Version
0
Version <
7.0
Status
unaffected
Version <=
6.1.*
Version
6.1.178
Status
unaffected
Version <=
6.6.*
Version
6.6.145
Status
unaffected
Version <=
6.12.*
Version
6.12.97
Status
unaffected
Version <=
6.18.*
Version
6.18.40
Status
unaffected
Version <=
7.1.*
Version
7.1.5
Status
unaffected
Version <=
*
Version
7.2
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.18% | 0.081 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | 8.4 | 2.5 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
https://git.kernel.org/stable/c/55fb9581986141659002264fdc75cef307811eb8
https://git.kernel.org/stable/c/4465ebe67d89345954bb3622b25dd13e06f9d367
https://git.kernel.org/stable/c/3baedc9b2f53e6a6ac57b16fdff0f9b954d9ca71
https://git.kernel.org/stable/c/21303c4a2b7275e626c6b67de0f45f2d5b9bb3e7
https://git.kernel.org/stable/c/7839f1817a0cb6c4ed5cfe25d04845c43380a129
https://git.kernel.org/stable/c/6d9a4aaaa8b2612b5ef9d581e2f286a458b71ee1