CVE-2026-98261: cifs: Fix server use-after-free in cifs_chan_skip_or_disable()
In the Linux kernel, the following vulnerability has been resolved:
cifs: Fix server use-after-free in cifschanskipordisable()
When a secondary channel is no longer supported by the server, cifschanskipordisable() drops the channel reference with cifsputtcpsession() and then continues to use the server pointer by calling cifssignalcifsdforreconnect() on it and reading its primaryserver pointer. cifsputtcpsession() can drop the last reference of the channel and tear it down, so both the channel and the primary server (whose reference is also dropped by cifsputtcpsession()) can be freed before they are signaled for reconnect.
Signal the channel and the primary server and capture the primary server pointer before dropping the channel reference with cifsputtcpsession().