{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89636","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.739Z","datePublished":"2026-09-11T19:45:30.283Z","dateUpdated":"2026-09-14T12:01:41.762Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-14T12:01:41.762Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: clear ce->tgthint in free_tgts()\n\nWhen free_tgts() frees all structures in ce->tlist, ce->tgthint\nis left pointing to one of the freed cache_dfs_tgt structures.\n\nIf ce->tgthint is not reset before it is used later, it results\nin a use-after-free.\n\nSet ce->tgthint to NULL in free_tgts() after the elements are\nfreed to reflect that no elements remain."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL"},"scenarios":[{"lang":"en","value":"AV:N - The dangling ce->tgthint is created while handling FSCTL_DFS_GET_REFERRALS/TRANS2_GET_DFS_REFERRAL replies from a remote SMB server over TCP/445 (smb2_get_dfs_refer → cache_refresh_path → update_cache_entry_locked → free_tgts). A malicious, compromised, or MITM'd DFS server reaches this purely over the network.\nAC:L - A hostile DFS server controls referral TTL (down to CACHE_MIN_TTL), target lists, and TCP resets that drive dfs_cache_refresh and reconnect into update_cache_entry_locked; after free_tgts() the later get_tgt_name()/dfs_cache_noreq_update_tgthint() use is deterministic, and the attacker can size and retry referrals to leave the stale hint and reclaim the slab.\nPR:N - The attacker is the remote SMB/DFS peer (or a MITM on an unsigned session) and needs no account, capability, or local privileges on the victim; the client authenticates to that server, and the kernel DFS cache parses the reply regardless of which local user owns the mount.\nUI:N - Once a DFS CIFS mount exists (fstab, autofs/systemd automount, enterprise DFS, cifsroot), dfs_cache_refresh delayed work and reconnect-driven cifs_tree_connect()/dfs_cache_noreq_find() use the stale tgthint automatically after a server-induced refresh or TCP drop, with no further user action.\nS:U - The use-after-free is of kmalloc'd cache_dfs_tgt objects in the client kernel heap and remains in the same host kernel security authority; it does not cross a VM, IOMMU, or sandbox boundary.\nC:H - get_tgt_name() and dfs_cache_noreq_update_tgthint() dereference the freed cache_dfs_tgt (t->name). Reclaiming that slab with attacker-controlled SMB allocations yields an arbitrary kernel read via kstrdup/strcasecmp of a sprayed name pointer.\nI:H - Use-after-free of the heap cache_dfs_tgt enables heap spraying and overlapping live objects; the dangling hint is also copied into DFS referral state and used for failover tree-connect, giving a write/control-flow primitive once the object is reclaimed.\nA:H - Dereferencing the freed cache_dfs_tgt from reconnect (cifs_tree_connect → dfs_cache_noreq_find) or dfs_cache_find oopses or panics the client kernel, and a malicious server can retrigger it on every refresh or reconnect."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/smb/client/dfs_cache.c"],"versions":[{"version":"54be1f6c1c37498bba557049df646cc239fa37e3","lessThan":"14f60e959b5ac813715ff72e127beb3584ddabf6","status":"affected","versionType":"git"},{"version":"54be1f6c1c37498bba557049df646cc239fa37e3","lessThan":"3ff9462bb7a06d8d32a1dc02d39580b078ec9e55","status":"affected","versionType":"git"},{"version":"54be1f6c1c37498bba557049df646cc239fa37e3","lessThan":"7507bd1885643d0461a6017767492450af1ce2a3","status":"affected","versionType":"git"},{"version":"54be1f6c1c37498bba557049df646cc239fa37e3","lessThan":"9ab46a13798a61d9d020b01d4e57efdabe6624fa","status":"affected","versionType":"git"},{"version":"54be1f6c1c37498bba557049df646cc239fa37e3","lessThan":"5baab40404a9393bcc0b7b8f1950bf2c307e0984","status":"affected","versionType":"git"},{"version":"54be1f6c1c37498bba557049df646cc239fa37e3","lessThan":"b1b741cf8e7ce1b91d937e23decd3d3358748700","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/smb/client/dfs_cache.c"],"versions":[{"version":"5.0","status":"affected"},{"version":"0","lessThan":"5.0","status":"unaffected","versionType":"semver"},{"version":"6.1.188","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.157","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.109","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.50","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.4","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.0","versionEndExcluding":"6.1.188"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.0","versionEndExcluding":"6.6.157"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.0","versionEndExcluding":"6.12.109"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.0","versionEndExcluding":"6.18.50"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.0","versionEndExcluding":"7.2.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.0","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/14f60e959b5ac813715ff72e127beb3584ddabf6"},{"url":"https://git.kernel.org/stable/c/3ff9462bb7a06d8d32a1dc02d39580b078ec9e55"},{"url":"https://git.kernel.org/stable/c/7507bd1885643d0461a6017767492450af1ce2a3"},{"url":"https://git.kernel.org/stable/c/9ab46a13798a61d9d020b01d4e57efdabe6624fa"},{"url":"https://git.kernel.org/stable/c/5baab40404a9393bcc0b7b8f1950bf2c307e0984"},{"url":"https://git.kernel.org/stable/c/b1b741cf8e7ce1b91d937e23decd3d3358748700"}],"title":"smb: client: clear ce->tgthint in free_tgts()","x_generator":{"engine":"bippy-1.2.0"}}}}