KernelScan.io

CRITICAL Introduced in 5.0

smb TgtHint UAF

CVE-2026-89636

CVSS 9.8 / 10.0 NVD

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

KernelScan AI8.1HIGH

01

In the Linux kernel, the following vulnerability has been resolved: smb: client: clear ce->tgthint in free_tgts() When free_tgts() frees all structures in ce->tlist, ce->tgthint is left pointing to one of the freed cache_dfs_tgt structures. If ce->tgthint is not reset before it is used later, it results in a use-after-free. Set ce->tgthint to NULL in free_tgts() after the elements are freed to reflect that no elements remain.

02

Engine v0.6.0

Risk summary

A use-after-free in the Linux SMB client's DFS cache can be triggered by a malicious or compromised SMB server when a victim has mounted a DFS-enabled share. The dangling target hint pointer may be dereferenced after cache flush or refresh, leading to kernel memory corruption. Systems that mount SMB shares with DFS referrals and are exposed to untrusted or semi-trusted servers are at risk.

Affectedfs/smb/client/dfs_cache.c (smb client dfs cache)

Vulnerability analysis

When the SMB client's DFS cache flushes or refreshes an entry, it frees all target structures in the entry's target list but leaves the target hint pointer dangling at one of the freed objects. If the client later uses that hint to select a connection target, it dereferences freed memory, resulting in a use-after-free. The fix clears the hint pointer after all targets are freed so subsequent lookups know no valid hint remains. This path is reachable whenever a system has mounted an SMB share that uses DFS referrals; a malicious or man-in-the-middle server can influence cache population and refresh timing through its referral responses, requiring no privileges on the victim beyond the initial mount.

03

BranchIntroducedFixed inPatch commit
6.65.06.6.1573ff9462bb7a0
6.125.06.12.1097507bd188564
6.185.06.18.509ab46a13798a
7.25.07.2.45baab40404a9
mainline5.07.3-rc1b1b741cf8e7c
6.15.06.1.18814f60e959b5a