CVE-2026-98175
Received
Received - Intake
Use-After-Free in Linux Kernel SMB Client
Vulnerability report for CVE-2026-98175, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-10-06
Last updated on: 2026-10-06
Assigner: kernel.org
Description
Description
In the Linux kernel, the following vulnerability has been resolved:
smb: client: cancel reconnect work in clean_demultiplex_info()
clean_demultiplex_info() cancels server->echo delayed work but not
server->reconnect, which can cause a use-after-free when the
demultiplex thread exits while a reconnect work is still queued:
cifs_demultiplex_thread()
cifs_readv_from_socket()
cifs_reconnect()
__cifs_reconnect()
cifs_queue_server_reconn()
mod_delayed_work(cifsiod_wq, &server->reconnect, 0)
clean_demultiplex_info()
cancel_delayed_work_sync(&server->echo) // echo canceled
// reconnect NOT canceled
kfree_sensitive(server) // server freed
...later, on cifsiod_wq:
smb2_reconnect_server()
server->srv_count // UAF read of freed server
Fix this by canceling server->reconnect delayed work in
clean_demultiplex_info() before the server is freed, the same way
cifs_put_tcp_session() already does.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| Linux | Linux | 53e0e11efe9289535b060a51d4cf37c25e0d0f2b |
| Linux | Linux | 53e0e11efe9289535b060a51d4cf37c25e0d0f2b |
| Linux | Linux | 53e0e11efe9289535b060a51d4cf37c25e0d0f2b |
| Linux | Linux | 53e0e11efe9289535b060a51d4cf37c25e0d0f2b |
| Linux | Linux | 53e0e11efe9289535b060a51d4cf37c25e0d0f2b |
| Linux | Linux | e008a962311a875a828cbae54b43285858aaa6c8 |
| Linux | Linux | 123b228a09b90b50b0a9d6eb8294cf0c42efc029 |
| Linux | Linux | 0ba4c6eaaacbcc4b18f51bb3b1567c65a8fecca9 |
| Linux | Linux | d0d2a4c82942e2f51e4984beea1f7e5a994bd06c |
| Linux | Linux | 15a12fbbf365a483b1c19f9caeb707b3bea77e10 |
| Linux | Linux | f0b715409cb9cf7e21e690f9b163047739761962 |
| Linux | Linux | ff04da387c10b6bf7b510392742c8cd46c130fd6 |
| Linux | Linux | 48f9526f4dcb4b132fe0dc2450835311e3b013a6 |
| Linux | Linux | 3.10.107 |
| Linux | Linux | 3.12.70 |
| Linux | Linux | 3.16.42 |
| Linux | Linux | 3.18.47 |
| Linux | Linux | 4.1.38 |
| Linux | Linux | 4.4.40 |
| Linux | Linux | 4.8.16 |
| Linux | Linux | 4.9.1 |
| Linux | Linux | 4.10 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |