CVE-2026-98175
Received Received - Intake

Use-After-Free in Linux Kernel SMB Client

Vulnerability report for CVE-2026-98175, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: smb: client: cancel reconnect work in clean_demultiplex_info() clean_demultiplex_info() cancels server->echo delayed work but not server->reconnect, which can cause a use-after-free when the demultiplex thread exits while a reconnect work is still queued: cifs_demultiplex_thread() cifs_readv_from_socket() cifs_reconnect() __cifs_reconnect() cifs_queue_server_reconn() mod_delayed_work(cifsiod_wq, &server->reconnect, 0) clean_demultiplex_info() cancel_delayed_work_sync(&server->echo) // echo canceled // reconnect NOT canceled kfree_sensitive(server) // server freed ...later, on cifsiod_wq: smb2_reconnect_server() server->srv_count // UAF read of freed server Fix this by canceling server->reconnect delayed work in clean_demultiplex_info() before the server is freed, the same way cifs_put_tcp_session() already does.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 22 associated CPEs
Vendor Product Version / Range
Linux Linux 53e0e11efe9289535b060a51d4cf37c25e0d0f2b
Linux Linux 53e0e11efe9289535b060a51d4cf37c25e0d0f2b
Linux Linux 53e0e11efe9289535b060a51d4cf37c25e0d0f2b
Linux Linux 53e0e11efe9289535b060a51d4cf37c25e0d0f2b
Linux Linux 53e0e11efe9289535b060a51d4cf37c25e0d0f2b
Linux Linux e008a962311a875a828cbae54b43285858aaa6c8
Linux Linux 123b228a09b90b50b0a9d6eb8294cf0c42efc029
Linux Linux 0ba4c6eaaacbcc4b18f51bb3b1567c65a8fecca9
Linux Linux d0d2a4c82942e2f51e4984beea1f7e5a994bd06c
Linux Linux 15a12fbbf365a483b1c19f9caeb707b3bea77e10
Linux Linux f0b715409cb9cf7e21e690f9b163047739761962
Linux Linux ff04da387c10b6bf7b510392742c8cd46c130fd6
Linux Linux 48f9526f4dcb4b132fe0dc2450835311e3b013a6
Linux Linux 3.10.107
Linux Linux 3.12.70
Linux Linux 3.16.42
Linux Linux 3.18.47
Linux Linux 4.1.38
Linux Linux 4.4.40
Linux Linux 4.8.16
Linux Linux 4.9.1
Linux Linux 4.10

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a use-after-free vulnerability in the Linux kernel's SMB client implementation. It occurs when clean_demultiplex_info() cancels only the echo delayed work but not the reconnect work, allowing the server structure to be freed while a reconnect operation is still queued. This can lead to a use-after-free when the reconnect work later tries to access the freed server structure.

Detection Guidance

This vulnerability is specific to the Linux kernel's CIFS/SMB client implementation. Detection requires checking if your system is running a vulnerable kernel version. Use 'uname -a' to check the kernel version. If your system is running a kernel version prior to the fix, it may be vulnerable.

Impact Analysis

This vulnerability could allow an attacker to cause a system crash or potentially execute arbitrary code with kernel privileges. It affects systems using the Linux kernel's SMB client functionality, which is commonly used for accessing Windows file shares or Samba servers.

Mitigation Strategies

Immediately update your Linux kernel to a version that includes the fix for this vulnerability. Check your distribution's security advisories for the patched kernel version. If updating is not immediately possible, consider disabling the CIFS/SMB client functionality until the update is applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-98175. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart