7.8

CVE-2026-89641

cifs: clear tcon after cifsFileInfo_put() in cifs_file_set_size()

In the Linux kernel, the following vulnerability has been resolved:

cifs: clear tcon after cifsFileInfo_put() in cifs_file_set_size()

When the else branch of cifs_file_set_size() finds a writable file handle
via find_writable_file(), it borrows tcon and server from the handle's
tlink, attempts the handle-based set_file_size() RPC, and then releases
the handle with cifsFileInfo_put().

If set_file_size() fails, execution falls through to the path-based
fallback, which reuses the borrowed tcon and server under the
"if (tcon == NULL)" guard.  Since tcon is not NULL at that point, the
guard is skipped.  If cifsFileInfo_put() dropped the last reference on a
tlink that was already removed from the tlink tree (TCON_LINK_IN_TREE
cleared, as happens during reconnection or session teardown),
cifs_put_tlink() will have freed tcon; the subsequent set_path_size()
call is then a use-after-free.

Setting tcon = NULL after cifsFileInfo_put() causes the existing guard
to take the cifs_sb_tlink() path, which acquires a fresh reference for
the path-based operation or fails cleanly if the session is gone.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 110fee6b9bb58a5c50047fc2594d415f741b591e
Version < 4f18c9e7ee464aaae5cd9fccdb943b3fcb4655d4
Status affected
Version 110fee6b9bb58a5c50047fc2594d415f741b591e
Version < 4bea15d9c7683218f57b8c1f5f0aa75cab76af8d
Status affected
Version 110fee6b9bb58a5c50047fc2594d415f741b591e
Version < b96db32fed8dfb2478d7c208f89bf383beed1535
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.18
Status affected
Version 0
Version < 6.18
Status unaffected
Version <= 6.18.*
Version 6.18.50
Status unaffected
Version <= 7.2.*
Version 7.2.4
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.14% 0.037
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/4f18c9e7ee464aaae5cd9fccdb943b3fcb4655d4
https://git.kernel.org/stable/c/4bea15d9c7683218f57b8c1f5f0aa75cab76af8d
https://git.kernel.org/stable/c/b96db32fed8dfb2478d7c208f89bf383beed1535