KernelScan.io

HIGH Introduced in 5.19

smb IfaceList UAF

CVE-2026-98173

CVSS 7.5 / 10.0 NVD

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

KernelScan AI7.0HIGH

01

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix use-after-free of iface in cifs_try_adding_channels() cifs_try_adding_channels() iterates ses->iface_list with list_for_each_entry_safe_from(), which captures the next entry (niface) under iface_lock. The loop body then drops iface_lock for the whole duration of cifs_ses_add_channel(). A concurrent interface refresh (SMB3_request_interfaces() -> parse_server_interfaces()) marks all ifaces inactive and removes and frees any that are not re-advertised via list_del() + kref_put(), where release_iface() is a bare kfree(). Since niface typically has no channel holding a reference, the list reference is its last and it can be freed inside the unlocked window. On continue, the iterator advance step then dereferences niface->iface_head.next, and the loop body reads iface->rdma_capable/is_active, both on freed memory. Fix this by never keeping an unreferenced list pointer across the unlocked window. Each channel attempt now re-scans the list from the head under iface_lock, takes a kref on the selected candidate, and passes only that referenced candidate to cifs_ses_add_channel(). weight_fulfilled still tracks selection progress, so restarting the scan preserves the original weighted distribution and the weight_fulfilled-before-kref_put ordering on the failure path. Add a per-pass attempts cap so a flapping interface refresh cannot keep the inner loop spinning within a single tries increment.

02

Engine v0.7.0

Risk summary

A local user with access to a mounted SMB3 share can trigger a use-after-free in the kernel's CIFS multichannel interface-list handling. A race between channel addition and interface refresh frees an object that the iterator still holds, leading to dereference of freed memory. This can crash the kernel or potentially be exploited for privilege escalation.

Affectedfs/smb/client/sess.c (smb3 client multichannel)

Vulnerability analysis

The SMB3 client's multichannel support contains a race between opening new channels and updating the list of server network interfaces. While one thread is midway through opening a channel, another can remove and free an interface object from the list; the first thread later touches that freed memory, causing a use-after-free. The repair removes the stale list pointer that was being carried across the vulnerable window. Instead, each attempt now safely rescans the list and acquires a proper reference on the chosen interface before proceeding with channel setup. The update also bounds retry attempts so an endlessly changing interface list cannot stall the driver. Any local user with access to a mounted SMB share can trigger the flaw, and a malicious or man-in-the-middle server can time its interface updates to widen the race window.

03

BranchIntroducedFixed inPatch commit
6.125.196.12.112c941f1ebfd26
6.185.196.18.54e99040e5e9c6
7.25.197.2.8ec36b38e6559
mainline5.197.3-rc4d034e836eefd