7.5
CVE-2026-98173
- EPSS 0.33%
- Veröffentlicht 06.10.2026 08:44:17
- Zuletzt bearbeitet 07.10.2026 07:17:03
- Erkennungen
smb: client: fix use-after-free of iface in cifs_try_adding_channels()
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix use-after-free of iface in cifs_try_adding_channels() cifs_try_adding_channels() iterates ses->iface_list with list_for_each_entry_safe_from(), which captures the next entry (niface) under iface_lock. The loop body then drops iface_lock for the whole duration of cifs_ses_add_channel(). A concurrent interface refresh (SMB3_request_interfaces() -> parse_server_interfaces()) marks all ifaces inactive and removes and frees any that are not re-advertised via list_del() + kref_put(), where release_iface() is a bare kfree(). Since niface typically has no channel holding a reference, the list reference is its last and it can be freed inside the unlocked window. On continue, the iterator advance step then dereferences niface->iface_head.next, and the loop body reads iface->rdma_capable/is_active, both on freed memory. Fix this by never keeping an unreferenced list pointer across the unlocked window. Each channel attempt now re-scans the list from the head under iface_lock, takes a kref on the selected candidate, and passes only that referenced candidate to cifs_ses_add_channel(). weight_fulfilled still tracks selection progress, so restarting the scan preserves the original weighted distribution and the weight_fulfilled-before-kref_put ordering on the failure path. Add a per-pass attempts cap so a flapping interface refresh cannot keep the inner loop spinning within a single tries increment.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
aa45dadd34e44fcd6a9df4b395bee5b5633b4cec
Version <
c941f1ebfd26f683de81091473f3596a218abff0
Status
affected
Version
aa45dadd34e44fcd6a9df4b395bee5b5633b4cec
Version <
e99040e5e9c60441e6b4725e1a7b88c3106ae903
Status
affected
Version
aa45dadd34e44fcd6a9df4b395bee5b5633b4cec
Version <
ec36b38e65596950e6c29bed7dfc90b98707c19c
Status
affected
Version
aa45dadd34e44fcd6a9df4b395bee5b5633b4cec
Version <
d034e836eefd7ce75e588f7031cffbeec594f5ac
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
5.19
Status
affected
Version
0
Version <
5.19
Status
unaffected
Version <=
6.12.*
Version
6.12.112
Status
unaffected
Version <=
6.18.*
Version
6.18.54
Status
unaffected
Version <=
7.2.*
Version
7.2.8
Status
unaffected
Version <=
*
Version
7.3-rc4
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.33% | 0.236 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | 7.5 | 1.6 | 5.9 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
|
https://git.kernel.org/stable/c/c941f1ebfd26f683de81091473f3596a218abff0
https://git.kernel.org/stable/c/e99040e5e9c60441e6b4725e1a7b88c3106ae903
https://git.kernel.org/stable/c/ec36b38e65596950e6c29bed7dfc90b98707c19c
https://git.kernel.org/stable/c/d034e836eefd7ce75e588f7031cffbeec594f5ac