CVE-2026-98173

Source
https://cve.org/CVERecord?id=CVE-2026-98173
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98173.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-98173
Downstream
Published
2026-10-06T08:44:17Z
Modified
2026-10-07T02:47:29Z
Summary
smb: client: fix use-after-free of iface in cifs_try_adding_channels()
Details

In the Linux kernel, the following vulnerability has been resolved:

smb: client: fix use-after-free of iface in cifs_try_adding_channels()

cifs_try_adding_channels() iterates ses->iface_list with list_for_each_entry_safe_from(), which captures the next entry (niface) under iface_lock. The loop body then drops iface_lock for the whole duration of cifs_ses_add_channel().

A concurrent interface refresh (SMB3_request_interfaces() -> parse_server_interfaces()) marks all ifaces inactive and removes and frees any that are not re-advertised via list_del() + kref_put(), where release_iface() is a bare kfree(). Since niface typically has no channel holding a reference, the list reference is its last and it can be freed inside the unlocked window. On continue, the iterator advance step then dereferences niface->iface_head.next, and the loop body reads iface->rdma_capable/is_active, both on freed memory.

Fix this by never keeping an unreferenced list pointer across the unlocked window. Each channel attempt now re-scans the list from the head under iface_lock, takes a kref on the selected candidate, and passes only that referenced candidate to cifs_ses_add_channel(). weight_fulfilled still tracks selection progress, so restarting the scan preserves the original weighted distribution and the weight_fulfilled-before-kref_put ordering on the failure path.

Add a per-pass attempts cap so a flapping interface refresh cannot keep the inner loop spinning within a single tries increment.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98173.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
aa45dadd34e44fcd6a9df4b395bee5b5633b4cec
Fixed
c941f1ebfd26f683de81091473f3596a218abff0
Fixed
e99040e5e9c60441e6b4725e1a7b88c3106ae903
Fixed
ec36b38e65596950e6c29bed7dfc90b98707c19c
Fixed
d034e836eefd7ce75e588f7031cffbeec594f5ac

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98173.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.19.0
Fixed
6.12.112
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.54
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98173.json"