Junglewise Threat Intelligence

CVE-2026-74608: Linux kernel use-after-free in cifs_try_adding_channels

CVE-2026-74608 · Severity: critical · CVSS 9.8 · Published 2026-08-22

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's SMB client contains a use-after-free vulnerability in channel management during SMB session setup. When channel creation fails, freed memory can be accessed, potentially allowing a denial of service or local privilege escalation on systems using the CIFS/SMB network filesystem client.

Technical details

This is a use-after-free vulnerability in the SMB client's cifs_try_adding_channels() function in fs/smb/client/sess.c. The vulnerable code path occurs when attempting to add additional SMB channels: after calling cifs_ses_add_channel() fails, the function releases a reference to an interface object via kref_put() and then attempts to increment the iface->weight_fulfilled field. A concurrent interface list refresh can remove the list reference between the failure and the field update, causing kref_put() to release the final reference and free the interface structure, leading to a use-after-free when weight_fulfilled is subsequently accessed. The fix reorders the operations to increment weight_fulfilled before dropping the reference, ensuring the interface object remains alive. This affects the Linux kernel's CIFS/SMB protocol implementation and requires local or network proximity to trigger.

Affected products

  • Linux Linux Kernel Multiple versions (patched in stable branches)

Timeline

  • 2026-08-22: disclosed
  • 2026-08-19: patched: Commit 4986410316b1ae0e63c6ce418e4eb196723626e7 upstream; backported to stable kernel branches

References

Related threats