Sceawere
Vulnerability Detail
CVE-2026-98173UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
CIFS Use-After-Free in cifs_try_adding_channels
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.5
- Creation Date
- 1d ago
- Vendor
- Linux
- Product
- Linux
- Attack Type
- N/A
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
- Attack Complexity
- HIGH
Narrative and Response
Description
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix use-after-free of iface in cifs_try_adding_channels() cifs_try_adding_channels() iterates ses->iface_list with list_for_each_entry_safe_from(), which captures the next entry (niface) under iface_lock. The loop body then drops iface_lock for the whole duration of cifs_ses_add_channel(). A concurrent interface refresh (SMB3_request_interfaces() -> parse_server_interfaces()) marks all ifaces inactive and removes and frees any that are not re-advertised via list_del() + kref_put(), where release_iface() is a bare kfree(). Since niface typically has no channel holding a reference, the list reference is its last and it can be freed inside the unlocked window. On continue, the iterator advance step then dereferences niface->iface_head.next, and the loop body reads iface->rdma_capable/is_active, both on freed memory. Fix this by never keeping an unreferenced list pointer across the unlocked window. Each channel attempt now re-scans the list from the head under iface_lock, takes a kref on the selected candidate, and passes only that referenced candidate to cifs_ses_add_channel(). weight_fulfilled still tracks selection progress, so restarting the scan preserves the original weighted distribution and the weight_fulfilled-before-kref_put ordering on the failure path. Add a per-pass attempts cap so a flapping interface refresh cannot keep the inner loop spinning within a single tries increment.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.5",
"pubDate": "2026-10-06T09:17:59.060Z",
"pubdate": "2026-10-06T09:17:59.060Z",
"executiveSummary": "A critical Use-After-Free (UAF) vulnerability exists within the Linux kernel CIFS client, specifically in the cifs_try_adding_channels() function.\nThe vulnerability stems from an unsafe iteration pattern over the ses->iface_list during concurrent interface management operations.\nThe flaw allows a race condition where an interface object is freed while the iterator still holds a pointer to it, leading to memory corruption or kernel panics.\nAttackers capable of triggering interface refresh events or manipulating network conditions could exploit this to induce a denial-of-service (DoS) condition or potentially gain elevated execution context.\nThe vulnerability impacts the SMB/CIFS network protocol implementation in the Linux kernel.\nSuccessful exploitation requires the ability to trigger internal kernel race conditions via concurrent operations on interface lists, typically involving active network traffic or interface flapping.",
"technicalDetails": "The vulnerability occurs within cifs_try_adding_channels() because it employs list_for_each_entry_safe_from() while dropping the iface_lock mutex during the execution of cifs_ses_add_channel().\nUnder normal circumstances, list_for_each_entry_safe_from() is intended to safely iterate over lists even if the current node is removed; however, it fails to account for scenarios where the 'next' entry (niface) is freed by another thread during the unlocked window.\nThe root cause is a race condition involving the SMB3_request_interfaces() and parse_server_interfaces() functions. When an interface refresh occurs, the kernel marks interfaces as inactive and performs list_del() followed by a kref_put(). If the reference count drops to zero, the object is immediately freed via kfree() inside release_iface().\nBecause the iteration mechanism in cifs_try_adding_channels() keeps a reference to the 'next' entry while the lock is dropped, the 'niface' pointer becomes a dangling pointer if the refresh logic happens to free that object before the loop resumes.\nWhen the iterator resumes, it attempts to access niface->iface_head.next, resulting in a dereference of freed kernel memory. Furthermore, subsequent loop iterations attempt to read attributes like rdma_capable or is_active from the freed memory address.\nExploitation involves inducing high-frequency interface updates concurrently with channel addition requests. By forcing the kernel to prune and free iface objects while the iterator is suspended, an attacker can manipulate kernel memory layouts or trigger a kernel panic due to the invalid memory access.\nThe impact includes system crashes, data corruption within the kernel heap, or unpredictable behavior in the CIFS client subsystem. The vulnerability is triggered during network interface management, implying it is exposed whenever the client interacts with a server supporting multi-channel SMB connections."
}