CVE-2026-98261
Received
Received - Intake
Use-After-Free in Linux Kernel CIFS
Vulnerability report for CVE-2026-98261, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-10-06
Last updated on: 2026-10-06
Assigner: kernel.org
Description
Description
In the Linux kernel, the following vulnerability has been resolved:
cifs: Fix server use-after-free in cifs_chan_skip_or_disable()
When a secondary channel is no longer supported by the server,
cifs_chan_skip_or_disable() drops the channel reference with
cifs_put_tcp_session() and then continues to use the server pointer by
calling cifs_signal_cifsd_for_reconnect() on it and reading its
primary_server pointer. cifs_put_tcp_session() can drop the last
reference of the channel and tear it down, so both the channel and the
primary server (whose reference is also dropped by
cifs_put_tcp_session()) can be freed before they are signaled for
reconnect.
Signal the channel and the primary server and capture the primary
server pointer before dropping the channel reference with
cifs_put_tcp_session().
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| Linux | Linux | 50e8363ecc85da49764781da90ebffe1a657b370 |
| Linux | Linux | f591062bdbf4742b7f1622173017f19e927057b0 |
| Linux | Linux | f591062bdbf4742b7f1622173017f19e927057b0 |
| Linux | Linux | f591062bdbf4742b7f1622173017f19e927057b0 |
| Linux | Linux | f591062bdbf4742b7f1622173017f19e927057b0 |
| Linux | Linux | d61ba1d71ea6039eca7ada870bf3f0c3c8fc12e4 |
| Linux | Linux | 6.6.15 |
| Linux | Linux | 6.7.3 |
| Linux | Linux | 6.8 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |