{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-98174","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-25T10:25:14.322Z","datePublished":"2026-10-06T08:44:18.350Z","dateUpdated":"2026-10-07T06:49:23.401Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-10-07T06:49:23.401Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: fix rlist race and missing initialization\n\nTCP_Server_Info.rlist is allocated via kzalloc which zeros both ->next\nand ->prev to NULL instead of pointing to itself, making list_empty()\nalways return false and list_add() dereference a NULL ->prev pointer.\n\nAlso, cifs_signal_cifsd_for_reconnect() can be called concurrently\nfrom multiple cifsd threads, allowing the same server's rlist node to\nbe added twice into the local list, corrupting it."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":7.5,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:N - The trigger is SMB transport data sent by the server: an unexpected RFC1002 frame type, or a framing or decrypt error, on two channels makes is_smb_response()/smb2ops call cifs_reconnect(server, true). That leads to __cifs_reconnect() -> cifs_signal_cifsd_for_reconnect(all_channels=true) in two cifsd threads at once. The server's TCP traffic is routable.\nAC:H - The attacker must get the two channels' list_add(&nserver->rlist, &reco) calls inside the short window after one thread drops cifs_tcp_ses_lock and before it finishes walking its on-stack reco list. Timing that from frames sent over the network is unreliable. The bug also needs a multichannel session (chan_count > 1), and that is not the default.\nPR:N - A malicious SMB server, or an on-path attacker on the client's SMB connections, needs no account on the victim host. The reconnect is triggered by RFC1002 frames that cifsd parses before any check on the server's authenticity.\nUI:R - A victim has to mount a share from the attacker's server with the non-default multichannel or max_channels>1 option. Otherwise ses->chan_count stays 1 and the loop over chans[1..] in cifs_signal_cifsd_for_reconnect() never adds anything to reco.\nS:U - The corruption is in the CIFS client's TCP_Server_Info list linkage and other kernel stack frames, inside the same kernel security authority. No guest/host, IOMMU or sandbox boundary is crossed.\nC:H - One TCP_Server_Info.rlist node ends up linked into two cifsd threads' on-stack reco lists. list_for_each_entry_safe() can then follow a pointer into another thread's stack, which may already be dead, and treat it as a TCP_Server_Info. That is kernel memory corruption that can be steered into reads of controlled memory.\nI:H - The bogus entry is passed to set_need_reco() (spin_lock and a tcpStatus write) and to cifs_put_tcp_session() (srv_count decrement and possible teardown and free). Those are kernel writes through a corrupted list pointer, the same class as list-corruption write primitives.\nA:H - With CONFIG_LIST_HARDENED/DEBUG_LIST, the first list_del_init() on the doubly linked rlist BUGs. Without it, the walk faults or loops on the corrupted reco list. The server can resend bad frames after every reconnect, so it can keep retrying until the client host crashes."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/smb/client/connect.c"],"versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"b5f924ffbfa976e4b97f17e8132c595b97482c2d","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"5a8f82f9c5839389cf4036029dd75a9911049e83","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"04082b1833856cb9ed87e0d3d5f04cbf836cf7da","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"c037d6bde3dd5fa00b017b6b98a5389ec0ebc02f","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"5f270f091256da1338c3631083e15d7f83cc05e1","status":"affected","versionType":"git"},{"version":"0","lessThan":"6.6.158","status":"affected","versionType":"semver"},{"version":"0","lessThan":"6.12.112","status":"affected","versionType":"semver"},{"version":"0","lessThan":"6.18.54","status":"affected","versionType":"semver"},{"version":"0","lessThan":"7.2.8","status":"affected","versionType":"semver"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/smb/client/connect.c"],"versions":[{"version":"6.6.158","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.112","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.54","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.8","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc4","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.6.158"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.12.112"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.18.54"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2.8"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.3-rc4"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/b5f924ffbfa976e4b97f17e8132c595b97482c2d"},{"url":"https://git.kernel.org/stable/c/5a8f82f9c5839389cf4036029dd75a9911049e83"},{"url":"https://git.kernel.org/stable/c/04082b1833856cb9ed87e0d3d5f04cbf836cf7da"},{"url":"https://git.kernel.org/stable/c/c037d6bde3dd5fa00b017b6b98a5389ec0ebc02f"},{"url":"https://git.kernel.org/stable/c/5f270f091256da1338c3631083e15d7f83cc05e1"}],"title":"smb: client: fix rlist race and missing initialization","x_generator":{"engine":"bippy-1.2.0"}}}}