{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-74608","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-08-15T05:44:03.920Z","datePublished":"2026-08-22T15:31:55.298Z","dateUpdated":"2026-08-25T05:40:33.533Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-25T05:40:33.533Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: Fix use-after-free in cifs_try_adding_channels()\n\ncifs_try_adding_channels() takes a temporary reference to an interface\nbefore dropping iface_lock. If cifs_ses_add_channel() fails, it drops\nthat reference and then increments iface->weight_fulfilled.\n\nA concurrent interface list refresh can remove the list reference while\nchannel creation is in progress. In that case, the failure-path\nkref_put() releases the last reference and frees iface. Updating\nweight_fulfilled afterward then accesses freed memory.\n\nIncrement weight_fulfilled before dropping the temporary reference,\nkeeping iface alive for the final access."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL"},"scenarios":[{"lang":"en","value":"AV:N - The flaw is in the kernel SMB3 client multichannel path reached while handling remote SMB/CIFS server traffic (channel setup, reconnect, and FSCTL_QUERY_NETWORK_INTERFACE_INFO responses) over TCP, so a malicious or compromised SMB server can trigger it from the network.\nAC:L - A hostile SMB server can force cifs_ses_add_channel() to fail and concurrently drive interface-list refresh during the unlocked window; the attacker controls both sides of the race via reconnects, binding failures, and crafted interface responses with retries.\nPR:N - The attacker only needs to operate the malicious SMB server peer; no credentials, local shell access, or privileges on the victim host are required once the client has an SMB3 multichannel session to that server.\nUI:N - After an SMB3 multichannel mount exists, kernel delayed query_interfaces work, automatic reconnect on dropped TCP, and post-mount channel scaling invoke cifs_try_adding_channels() without further user action, letting the server trigger exploitation repeatedly.\nS:U - The UAF corrupts client kernel heap state within the same host kernel security authority and does not inherently cross a VM, container, or IOMMU security boundary.\nC:H - Writing to a freed cifs_server_iface slab object is a use-after-free; attacker-influenced heap grooming can reclaim the object and enable arbitrary kernel memory disclosure via corrupted or overlapping live allocations.\nI:H - The post-free weight_fulfilled increment is a kernel heap write after free that can corrupt adjacent slab objects and be leveraged into arbitrary write or control-flow hijacking through heap shaping.\nA:H - The use-after-free can cause KASAN-detectable slab corruption, kernel oops, or panic, and a malicious server can retrigger it by repeating failed channel opens with concurrent interface-list refresh on reconnect."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/smb/client/sess.c"],"versions":[{"version":"cbc53148cc0946b72d62a3c53870cb22ce4ec284","lessThan":"64d7584e62ac8cdc750455c5fdc6008fc2de4f06","status":"affected","versionType":"git"},{"version":"cff97d683a083b862a8bb24309e0f4d2d928128a","lessThan":"c292d4686f717c03e5022fc4ae7c782f39a94915","status":"affected","versionType":"git"},{"version":"6aac002bcfd554aff6d3ebb55e1660d078d70ab0","lessThan":"47dfac48bce7198ad4f1a388fc8c9491f878ac3b","status":"affected","versionType":"git"},{"version":"6aac002bcfd554aff6d3ebb55e1660d078d70ab0","lessThan":"1ffacbadc14530e55b8d86f7b917524f6a0fb891","status":"affected","versionType":"git"},{"version":"6aac002bcfd554aff6d3ebb55e1660d078d70ab0","lessThan":"1305eadc6a7d78a8d0a52eee29ddd2d9e8a27805","status":"affected","versionType":"git"},{"version":"6aac002bcfd554aff6d3ebb55e1660d078d70ab0","lessThan":"4986410316b1ae0e63c6ce418e4eb196723626e7","status":"affected","versionType":"git"},{"version":"22a6c5b3425f327e7f4c3606a72277dce82c7d83","status":"affected","versionType":"git"},{"version":"6.1.78","lessThan":"6.1.183","status":"affected","versionType":"semver"},{"version":"6.6.17","lessThan":"6.6.152","status":"affected","versionType":"semver"},{"version":"6.7.5","lessThan":"6.8","status":"affected","versionType":"semver"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/smb/client/sess.c"],"versions":[{"version":"6.8","status":"affected"},{"version":"0","lessThan":"6.8","status":"unaffected","versionType":"semver"},{"version":"6.1.183","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.152","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.104","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","status":"unaffected","versionType":"semver"},{"version":"7.2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.1.78","versionEndExcluding":"6.1.183"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.6.17","versionEndExcluding":"6.6.152"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.8","versionEndExcluding":"6.12.104"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.8","versionEndExcluding":"6.18.45"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.8","versionEndExcluding":"7.1.9"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.8","versionEndExcluding":"7.2"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.7.5"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/64d7584e62ac8cdc750455c5fdc6008fc2de4f06"},{"url":"https://git.kernel.org/stable/c/c292d4686f717c03e5022fc4ae7c782f39a94915"},{"url":"https://git.kernel.org/stable/c/47dfac48bce7198ad4f1a388fc8c9491f878ac3b"},{"url":"https://git.kernel.org/stable/c/1ffacbadc14530e55b8d86f7b917524f6a0fb891"},{"url":"https://git.kernel.org/stable/c/1305eadc6a7d78a8d0a52eee29ddd2d9e8a27805"},{"url":"https://git.kernel.org/stable/c/4986410316b1ae0e63c6ce418e4eb196723626e7"}],"title":"smb: client: Fix use-after-free in cifs_try_adding_channels()","x_generator":{"engine":"bippy-1.2.0"}}}}