GHSA-MFC9-MFPP-WWCF

Vulnerability from github – Published: 2026-10-06 09:31 – Updated: 2026-10-07 09:32
VLAI
Details

In the Linux kernel, the following vulnerability has been resolved:

cifs: Fix server use-after-free in cifs_chan_skip_or_disable()

When a secondary channel is no longer supported by the server, cifs_chan_skip_or_disable() drops the channel reference with cifs_put_tcp_session() and then continues to use the server pointer by calling cifs_signal_cifsd_for_reconnect() on it and reading its primary_server pointer. cifs_put_tcp_session() can drop the last reference of the channel and tear it down, so both the channel and the primary server (whose reference is also dropped by cifs_put_tcp_session()) can be freed before they are signaled for reconnect.

Signal the channel and the primary server and capture the primary server pointer before dropping the channel reference with cifs_put_tcp_session().

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2026-98261"
  ],
  "database_specific": {
    "cwe_ids": [],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2026-10-06T09:18:15Z",
    "severity": "HIGH"
  },
  "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncifs: Fix server use-after-free in cifs_chan_skip_or_disable()\n\nWhen a secondary channel is no longer supported by the server,\ncifs_chan_skip_or_disable() drops the channel reference with\ncifs_put_tcp_session() and then continues to use the server pointer by\ncalling cifs_signal_cifsd_for_reconnect() on it and reading its\nprimary_server pointer. cifs_put_tcp_session() can drop the last\nreference of the channel and tear it down, so both the channel and the\nprimary server (whose reference is also dropped by\ncifs_put_tcp_session()) can be freed before they are signaled for\nreconnect.\n\nSignal the channel and the primary server and capture the primary\nserver pointer before dropping the channel reference with\ncifs_put_tcp_session().",
  "id": "GHSA-mfc9-mfpp-wwcf",
  "modified": "2026-10-07T09:32:15Z",
  "published": "2026-10-06T09:31:32Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-98261"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/0338489960ddad6368bce55e8adbc176c523093d"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/717e0a25036b6c92cecace30913b2d874a4c22b8"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/7a1b27780b113583a94256d58dabfe7c0d9286e7"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/edd52eae5fcfb8433b6bb0e7cd98db438fe01227"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/fcc0a935bb6e37ecbf7e4335061309f896f35780"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ]
}



Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Forecast uses a logistic model when the trend is rising, or an exponential decay model when the trend is falling. Fitted via linearized least squares.

Sightings

Author Source Type Date Other

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or observed by the user.
  • Confirmed: The vulnerability has been validated from an analyst's perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
  • Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
  • Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
  • Not confirmed: The user expressed doubt about the validity of the vulnerability.
  • Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.

Loading…

Loading…

Loading…

Related by attack behaviour

Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.


Loading…