Sceawere
Vulnerability Detail
CVE-2026-98261UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
CIFS Use-After-Free in cifs_chan_skip_or_disable
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.1
- Creation Date
- 1d ago
- Vendor
- Linux
- Product
- Linux
- Attack Type
- N/A
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- HIGH
Narrative and Response
Description
In the Linux kernel, the following vulnerability has been resolved: cifs: Fix server use-after-free in cifs_chan_skip_or_disable() When a secondary channel is no longer supported by the server, cifs_chan_skip_or_disable() drops the channel reference with cifs_put_tcp_session() and then continues to use the server pointer by calling cifs_signal_cifsd_for_reconnect() on it and reading its primary_server pointer. cifs_put_tcp_session() can drop the last reference of the channel and tear it down, so both the channel and the primary server (whose reference is also dropped by cifs_put_tcp_session()) can be freed before they are signaled for reconnect. Signal the channel and the primary server and capture the primary server pointer before dropping the channel reference with cifs_put_tcp_session().
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.1",
"pubDate": "2026-10-06T09:18:15.200Z",
"pubdate": "2026-10-06T09:18:15.200Z",
"executiveSummary": "This vulnerability is a use-after-free (UAF) flaw residing in the Linux kernel CIFS client, specifically within the cifs_chan_skip_or_disable() function.\nThe issue arises from improper reference counting when handling secondary channels, leading to premature memory deallocation of the server structures while they are still being referenced.\nAn attacker capable of triggering specific channel state transitions can induce a race condition, resulting in an invalid memory access.\nThe impact includes potential kernel panic (Denial of Service) or arbitrary code execution, depending on memory state at the time of the UAF.\nThe vulnerability affects kernel versions utilizing the cifs module for SMB/CIFS communication where secondary channels are enabled.\nExploitation requires the ability to interact with the SMB mount and force a condition where a secondary channel is no longer supported by the server, necessitating network access to the CIFS service.",
"technicalDetails": "The root cause of this vulnerability is a lifetime management error in the function cifs_chan_skip_or_disable(). When a secondary channel is decommissioned, the kernel calls cifs_put_tcp_session() to decrement the channel reference count.\nIn the vulnerable implementation, cifs_put_tcp_session() is invoked before the function completes its operations on the server and primary_server pointers. Because cifs_put_tcp_session() may trigger the final teardown of the TCP session and the associated server structure if the reference count hits zero, the subsequent accesses to the 'server' pointer and 'primary_server' pointer are performed on freed memory.\nSpecifically, the function proceeds to call cifs_signal_cifsd_for_reconnect(server) and attempts to read server->primary_server after the memory has already been freed. This creates a classic use-after-free condition.\nThe attack flow involves: 1) Establishing a CIFS connection with multiple channels; 2) Triggering an event that causes the server to stop supporting a specific secondary channel (e.g., through network-level session manipulation or protocol-specific flags); 3) The kernel driver executes cifs_chan_skip_or_disable(), where it prematurely calls cifs_put_tcp_session(); 4) The kernel frees the 'server' and 'primary_server' memory blocks; 5) The execution flow continues, dereferencing the dangling pointer to signal for a reconnect. This dereference leads to a memory corruption event or a kernel oops.\nThe vulnerable component is the cifs network filesystem implementation within the Linux kernel. The issue exists due to the lack of order-of-operations synchronization regarding reference counting. The memory region previously occupied by the 'server' object may be reallocated by other kernel subsystems before the signal for reconnect occurs, potentially allowing for controlled modification of the execution flow if an attacker can predict or influence slab cache allocation patterns.\nThis vulnerability does not require local user privileges if the attacker can influence the state of the SMB mount, though it is primarily an issue for systems acting as CIFS clients. The exposure is limited to the local kernel memory space, but successful exploitation typically results in immediate system instability."
}