Answer in brief
CVE-2026-98175 records a Unknown severity vulnerability in smb: client: cancel reconnect work in clean_demultiplex_info(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=53e0e11efe9289535b060a51d4cf37c25e0d0f2b <180380272f116dbd2b0354c5c7872e112e519149 || >=53e0e11efe9289535b060a51d4cf37c25e0d0f2b <e3f6a779433d13aafb5edab59e4f9313051e8a52 || >=53e0e11efe9289535b060a51d4cf37c25e0d0f2b <7ab9ceedd860216fb97f2d8574cbe58b8906f42a || >=53e0e11efe9289535b060a51d4cf37c25e0d0f2b <2e5103e11a17c274715dd56cf185eeedccf686b8 || >=53e0e11efe9289535b060a51d4cf37c25e0d0f2b <c65eae6f61d1778ff7a82e4aae4080e26f486af1 || e008a962311a875a828cbae54b43285858aaa6c8 || 123b228a09b90b50b0a9d6eb8294cf0c42efc029 || 0ba4c6eaaacbcc4b18f51bb3b1567c65a8fecca9 || d0d2a4c82942e2f51e4984beea1f7e5a994bd06c || 15a12fbbf365a483b1c19f9caeb707b3bea77e10 || f0b715409cb9cf7e21e690f9b163047739761962 || ff04da387c10b6bf7b510392742c8cd46c130fd6 || 48f9526f4dcb4b132fe0dc2450835311e3b013a6 || >=3.10.107 <3.11 || >=3.12.70 <3.13 || >=3.16.42 <3.17 || >=3.18.47 <3.19 || >=4.1.38 <4.2 || >=4.4.40 <4.5 || >=4.8.16 <4.9 || >=4.9.1 <4.10 | 180380272f116dbd2b0354c5c7872e112e519149, e3f6a779433d13aafb5edab59e4f9313051e8a52, 7ab9ceedd860216fb97f2d8574cbe58b8906f42a, 2e5103e11a17c274715dd56cf185eeedccf686b8, c65eae6f61d1778ff7a82e4aae4080e26f486af1, 3.11, 3.13, 3.17, 3.19, 4.2, 4.5, 4.9, 4.10 |
| Linux/Linuxgeneric | 4.10 | Not reported |
Published upstream
Oct 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Oct 6, 2026
In the Linux kernel, the following vulnerability has been resolved: smb: client: cancel reconnect work in clean_demultiplex_info() clean_demultiplex_info() cancels server->echo delayed work but not server->reconnect, which can cause a use-after-free when the demultiplex thread exits while a reconnect work is still queued: cifs_demultiplex_thread() cifs_readv_from_socket() cifs_reconnect() __cifs_reconnect() cifs_queue_server_reconn() mod_delayed_work(cifsiod_wq, &server->reconnect, 0) clean_demultiplex_info() cancel_delayed_work_sync(&server->echo) // echo canceled // reconnect NOT canceled kfree_sensitive(server) // server freed ...later, on cifsiod_wq: smb2_reconnect_server() server->srv_count // UAF read of freed server Fix this by canceling server->reconnect delayed work in clean_demultiplex_info() before the server is freed, the same way cifs_put_tcp_session() already does.
Quoted source text, attributed separately from HOL analysis.