Answer in brief
CVE-2026-98173 records a Unknown severity vulnerability in smb: client: fix use-after-free of iface in cifs_try_adding_channels(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=aa45dadd34e44fcd6a9df4b395bee5b5633b4cec <c941f1ebfd26f683de81091473f3596a218abff0 || >=aa45dadd34e44fcd6a9df4b395bee5b5633b4cec <e99040e5e9c60441e6b4725e1a7b88c3106ae903 || >=aa45dadd34e44fcd6a9df4b395bee5b5633b4cec <ec36b38e65596950e6c29bed7dfc90b98707c19c || >=aa45dadd34e44fcd6a9df4b395bee5b5633b4cec <d034e836eefd7ce75e588f7031cffbeec594f5ac | c941f1ebfd26f683de81091473f3596a218abff0, e99040e5e9c60441e6b4725e1a7b88c3106ae903, ec36b38e65596950e6c29bed7dfc90b98707c19c, d034e836eefd7ce75e588f7031cffbeec594f5ac |
| Linux/Linuxgeneric | 5.19 | Not reported |
Published upstream
Oct 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Oct 6, 2026
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix use-after-free of iface in cifs_try_adding_channels() cifs_try_adding_channels() iterates ses->iface_list with list_for_each_entry_safe_from(), which captures the next entry (niface) under iface_lock. The loop body then drops iface_lock for the whole duration of cifs_ses_add_channel(). A concurrent interface refresh (SMB3_request_interfaces() -> parse_server_interfaces()) marks all ifaces inactive and removes and frees any that are not re-advertised via list_del() + kref_put(), where release_iface() is a bare kfree(). Since niface typically has no channel holding a reference, the list reference is its last and it can be freed inside the unlocked window. On continue, the iterator advance step then dereferences niface->iface_head.next, and the loop body reads iface->rdma_capable/is_active, both on freed memory. Fix this by never keeping an unreferenced list pointer across the unlocked window. Each channel attempt now re-scans the list from the head under iface_lock, takes a kref on the selected candidate, and passes only that referenced candidate to cifs_ses_add_channel(). weight_fulfilled still tracks selection progress, so restarting the scan preserves the original weighted distribution and the weight_fulfilled-before-kref_put ordering on the failure path. Add a per-pass attempts cap so a flapping interface refresh cannot keep the inner loop spinning within a single tries increment.
Quoted source text, attributed separately from HOL analysis.