Executive brief
The Linux kernel's SMB client contains a use-after-free vulnerability in channel management during SMB session setup. When channel creation fails, freed memory can be accessed, potentially allowing a denial of service or local privilege escalation on systems using the CIFS/SMB network filesystem client.
Technical details
This is a use-after-free vulnerability in the SMB client's cifs_try_adding_channels() function in fs/smb/client/sess.c. The vulnerable code path occurs when attempting to add additional SMB channels: after calling cifs_ses_add_channel() fails, the function releases a reference to an interface object via kref_put() and then attempts to increment the iface->weight_fulfilled field. A concurrent interface list refresh can remove the list reference between the failure and the field update, causing kref_put() to release the final reference and free the interface structure, leading to a use-after-free when weight_fulfilled is subsequently accessed. The fix reorders the operations to increment weight_fulfilled before dropping the reference, ensuring the interface object remains alive. This affects the Linux kernel's CIFS/SMB protocol implementation and requires local or network proximity to trigger.
Affected products
- Linux Linux Kernel Multiple versions (patched in stable branches)
Timeline
- 2026-08-22: disclosed
- 2026-08-19: patched: Commit 4986410316b1ae0e63c6ce418e4eb196723626e7 upstream; backported to stable kernel branches