CVE-2026-89636

Source
https://cve.org/CVERecord?id=CVE-2026-89636
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89636.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-89636
Downstream
Published
2026-09-11T19:45:30Z
Modified
2026-09-13T03:47:20Z
Summary
smb: client: clear ce->tgthint in free_tgts()
Details

In the Linux kernel, the following vulnerability has been resolved:

smb: client: clear ce->tgthint in free_tgts()

When free_tgts() frees all structures in ce->tlist, ce->tgthint is left pointing to one of the freed cache_dfs_tgt structures.

If ce->tgthint is not reset before it is used later, it results in a use-after-free.

Set ce->tgthint to NULL in free_tgts() after the elements are freed to reflect that no elements remain.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89636.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
54be1f6c1c37498bba557049df646cc239fa37e3
Fixed
7507bd1885643d0461a6017767492450af1ce2a3
Fixed
9ab46a13798a61d9d020b01d4e57efdabe6624fa
Fixed
5baab40404a9393bcc0b7b8f1950bf2c307e0984
Fixed
b1b741cf8e7ce1b91d937e23decd3d3358748700

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89636.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.0.0
Fixed
6.12.109
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.50
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89636.json"