CVE-2026-98172: smb: client: fix smbd_connection leak on cifs_get_tcp_session() error
In the Linux kernel, the following vulnerability has been resolved:
smb: client: fix smbdconnection leak on cifsgettcpsession() error
When an RDMA connection is successfully established via smbdgetconnection() but cifsgettcpsession() later fails (e.g. kthreadcreate() returns an error), the error path frees tcpses without first destroying the smbdconnection.
Fix this by calling smbddestroy() in the outerr cleanup path before kfree(tcpses). smbddestroy() safely handles the case where smbdconn is NULL, so it can be called unconditionally.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
In the cifs_get_tcp_session() error cleanup path, call smbd_destroy() unconditionally before kfree(tcp_ses), so the smbd_connection is destroyed before the session is freed.