Sceawere
Vulnerability Detail
CVE-2026-98174UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Linux Kernel SMB Race Condition
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.5
- Creation Date
- 1d ago
- Vendor
- Linux
- Product
- Linux
- Attack Type
- N/A
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
- Attack Complexity
- HIGH
Narrative and Response
Description
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix rlist race and missing initialization TCP_Server_Info.rlist is allocated via kzalloc which zeros both ->next and ->prev to NULL instead of pointing to itself, making list_empty() always return false and list_add() dereference a NULL ->prev pointer. Also, cifs_signal_cifsd_for_reconnect() can be called concurrently from multiple cifsd threads, allowing the same server's rlist node to be added twice into the local list, corrupting it.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.5",
"pubDate": "2026-10-06T09:17:59.220Z",
"pubdate": "2026-10-06T09:17:59.220Z",
"executiveSummary": "The vulnerability involves a race condition and memory initialization failure within the Linux kernel CIFS/SMB client subsystem.\nSpecifically, the TCP_Server_Info.rlist structure suffers from incorrect list initialization, where pointers are set to NULL rather than self-referential, and a lack of synchronization in the cifs_signal_cifsd_for_reconnect function.\nThese flaws lead to potential memory corruption, kernel panics, or system crashes when multiple cifsd threads concurrently attempt to manage reconnect operations.\nThe vulnerability affects systems utilizing the Linux kernel SMB client. An attacker capable of triggering frequent reconnection events may successfully exploit the race condition to destabilize the kernel or induce a denial-of-service state.\nExploitation does not necessarily require advanced administrative privileges if an attacker can manipulate network traffic to force repeated CIFS reconnections, though successful exploitation typically results in system instability rather than arbitrary code execution.",
"technicalDetails": "The primary root cause of this vulnerability lies in the improper initialization of the rlist member within the TCP_Server_Info structure. The structure utilizes kzalloc for memory allocation, which effectively zero-initializes the list_head structure. In the Linux kernel's list implementation, a properly initialized empty list must have its next and prev pointers reference the head itself. By zeroing these to NULL, the kernel's list_empty() macro incorrectly evaluates to false, and subsequent list_add() operations attempt to dereference a NULL pointer during the modification of the ->prev member, leading to a null pointer dereference panic.\nThe second component of the vulnerability is a concurrency defect within the cifs_signal_cifsd_for_reconnect() function. This function lacks sufficient locking mechanisms to handle concurrent invocations across multiple cifsd threads. When multiple threads are triggered simultaneously, they compete to insert the same server's rlist node into a local list. Because the insertion process is not atomic and lacks serialization, the list integrity is compromised, leading to double-insertion or structural corruption of the linked list.\nThe attack flow proceeds as follows: An attacker induces a series of network disruptions or specifically crafted responses that force the SMB client to undergo repeated reconnection sequences. This triggers the cifs_signal_cifsd_for_reconnect() function across multiple kernel threads. Due to the lack of synchronization, the threads attempt to perform list operations on a malformed list head. If a thread attempts to add an item to the corrupted list, the kernel encounters an inconsistent state. The mismatch between the NULL-initialized pointers and the expected structure leads to a memory access violation or kernel heap corruption.\nThe vulnerable component is the SMB client implementation in the Linux kernel, specifically regarding the handling of TCP_Server_Info objects and their associated reconnection lists. The vulnerability exposes the kernel to high-severity denial-of-service conditions, as the resulting kernel oops or panic will inevitably crash the host system. Post-exploitation impact is focused on service availability, as the system becomes unresponsive or forces a reboot to recover from the faulted state."
}