Executive brief
A race condition was identified in the Linux kernel's SMB client (CIFS) that could lead to system instability or crashes. The issue occurs when the system fails to properly lock internal counters while managing network connections to file shares. This could potentially be exploited to cause a denial-of-service, affecting the availability of systems relying on SMB network storage.
Technical details
A race condition exists in the Linux kernel SMB client (CIFS/SMB2) within the 'smb2_find_smb_sess_tcon_unlocked' function in 'fs/smb/client/smb2transport.c'. The vulnerability stems from a missing spin_lock around the increment of 'tc_count' (tree connection reference count). This flaw was introduced during a refactoring that moved from 'cifs_tcp_ses_lock' to 'tc_lock'. An attacker with local access could potentially trigger concurrent access to this counter, leading to reference count corruption, which typically results in use-after-free scenarios or kernel panics (Denial of Service). Patches have been backported to multiple stable kernel branches.
Affected products
- Linux Linux Kernel 6.6.128 to 6.6.142, 6.12.75 to 6.12.92, 6.18.16 to 6.18.34, 6.19.6 to 7.0.11
Timeline
- 2026-05-14: other: Vulnerability fixed in upstream commits
- 2026-07-19: disclosed: CVE published to NVD
References
- https://git.kernel.org/stable/c/13fb413ae22a37c69341918a6d651d19a9b0b9b7
- https://git.kernel.org/stable/c/4d8690dace005a38e6dbde9ecce2da3ad85c7c41
- https://git.kernel.org/stable/c/7df1df6f40c0720d30206aa35c0343b962350e0d
- https://git.kernel.org/stable/c/bf4ebdb19ff9b3cdf992b50715fe61633327416a
- https://git.kernel.org/stable/c/e374f4e496fef8168784f93a4477d67be34485fd