Sceawere
Vulnerability Detail
CVE-2026-98175UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Use-After-Free in SMB Client
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.5
- Creation Date
- 1d ago
- Vendor
- Linux
- Product
- Linux
- Attack Type
- N/A
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
- Attack Complexity
- HIGH
Narrative and Response
Description
In the Linux kernel, the following vulnerability has been resolved: smb: client: cancel reconnect work in clean_demultiplex_info() clean_demultiplex_info() cancels server->echo delayed work but not server->reconnect, which can cause a use-after-free when the demultiplex thread exits while a reconnect work is still queued: cifs_demultiplex_thread() cifs_readv_from_socket() cifs_reconnect() __cifs_reconnect() cifs_queue_server_reconn() mod_delayed_work(cifsiod_wq, &server->reconnect, 0) clean_demultiplex_info() cancel_delayed_work_sync(&server->echo) // echo canceled // reconnect NOT canceled kfree_sensitive(server) // server freed ...later, on cifsiod_wq: smb2_reconnect_server() server->srv_count // UAF read of freed server Fix this by canceling server->reconnect delayed work in clean_demultiplex_info() before the server is freed, the same way cifs_put_tcp_session() already does.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.5",
"pubDate": "2026-10-06T09:17:59.477Z",
"pubdate": "2026-10-06T09:17:59.477Z",
"executiveSummary": "A use-after-free vulnerability exists in the Linux kernel's SMB client implementation within the demultiplexing process.\nThe vulnerability stems from improper cleanup of the reconnect worker thread during the teardown of the TCP session.\nAn attacker can trigger this vulnerability by causing the demultiplex thread to exit while a reconnection attempt is queued, leading to a race condition.\nSuccessful exploitation allows for a use-after-free scenario, which can result in kernel memory corruption, system instability, or potential arbitrary code execution with kernel-level privileges.\nThe affected component is the SMB client networking code specifically associated with server session management.\nRisk implications are high as the vulnerability targets core kernel memory management and synchronization logic, requiring minimal interaction to trigger if a network connection state is manipulated to force a disconnect during the teardown sequence.",
"technicalDetails": "The vulnerability resides in the clean_demultiplex_info() function within the Linux kernel's SMB client component. The root cause is a failure to synchronize the lifecycle of the server->reconnect delayed work item before the associated TCP session object is deallocated.\nIn the current implementation, clean_demultiplex_info() correctly invokes cancel_delayed_work_sync() for the server->echo worker, but it fails to perform the same operation for the server->reconnect work item. When the cifs_demultiplex_thread terminates, the teardown logic proceeds to call kfree_sensitive(server), effectively freeing the memory allocated for the TCP session.\nIf a network event or error triggers the cifs_reconnect() path, the kernel calls mod_delayed_work() to queue the reconnect work on the cifsiod_wq. Because the work is queued asynchronously, a window exists between the termination of the demultiplexing thread and the potential execution of the queued reconnect task.\nThe exploitation flow is as follows: 1) The client experiences a network disruption, triggering cifs_reconnect() and queuing the reconnect work item. 2) The demultiplex thread encounters an exit condition and initiates the cleanup via clean_demultiplex_info(). 3) The cleanup function cancels the echo task and releases the memory allocated for the server object. 4) The cifsiod_wq scheduler later executes smb2_reconnect_server(). 5) This function attempts to dereference the server object (e.g., accessing server->srv_count), which now points to freed memory (use-after-free).\nThis leads to an invalid memory access or a kernel oops. If an attacker can control or groom the heap layout before the use-after-free occurs, they may achieve arbitrary code execution by redirecting kernel control flow or overwriting sensitive data structures residing at the memory address previously occupied by the server object. This vulnerability impacts the stability and security of the Linux kernel's SMB implementation, specifically affecting versions that do not include the explicit cancellation of the reconnect work in the session teardown procedure."
}