CVE-2026-98173: smb: client: fix use-after-free of iface in cifs_try_adding_channels()

Published Oct 6, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

smb: client: fix use-after-free of iface in cifstryaddingchannels()

cifstryaddingchannels() iterates ses->ifacelist with listforeachentrysafefrom(), which captures the next entry (niface) under ifacelock. The loop body then drops ifacelock for the whole duration of cifssesaddchannel().

A concurrent interface refresh (SMB3requestinterfaces() -> parseserverinterfaces()) marks all ifaces inactive and removes and frees any that are not re-advertised via listdel() + krefput(), where releaseiface() is a bare kfree(). Since niface typically has no channel holding a reference, the list reference is its last and it can be freed inside the unlocked window. On continue, the iterator advance step then dereferences niface->ifacehead.next, and the loop body reads iface->rdmacapable/isactive, both on freed memory.

Fix this by never keeping an unreferenced list pointer across the unlocked window. Each channel attempt now re-scans the list from the head under ifacelock, takes a kref on the selected candidate, and passes only that referenced candidate to cifssesaddchannel(). weightfulfilled still tracks selection progress, so restarting the scan preserves the original weighted distribution and the weightfulfilled-before-krefput ordering on the failure path.

Add a per-pass attempts cap so a flapping interface refresh cannot keep the inner loop spinning within a single tries increment.

Affected Software

1 affected component
Linux Linux kernel

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Compensating control

    Update cifs_try_adding_channels() so each channel attempt selects a candidate while holding iface_lock, takes a kref before releasing the lock, keeps that reference for the entire cifs_ses_add_channel() call, and adds a per-pass attempts cap so a flapping interface refresh cannot keep the loop spinning.

Event History

Oct 6, 2026
CVE Published
via MITRE·08:44 AM
Data Sourced
via MITRE·08:44 AM
DescriptionSeverity
Data Sourced
via NVD·09:17 AM
DescriptionSeverity
Oct 7, 2026
Data Sourced
via Microsoft·08:27 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What conditions are required for this issue to occur?

The affected SMB client must be attempting to add channels while a concurrent SMB3 interface refresh updates the server interface list. Exploitation also depends on the race occurring during the period when the interface-list lock is released for cifs_ses_add_channel().

2

Is an attacker required to have local access or credentials?

The CVSS vector identifies network reachability, no privileges, and user interaction as required. The supplied details do not specify what user action triggers the vulnerable SMB client behavior.

3

How can I tell whether a system has the fix?

The fix changes cifs_try_adding_channels() so that it re-scans the interface list while holding iface_lock and takes a kref on the selected interface before calling cifs_ses_add_channel(). The listed stable kernel references contain the corresponding fixes.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203