Junglewise Threat Intelligence

CVE-2026-89641: Linux kernel CIFS use-after-free in cifs_file_set_size()

CVE-2026-89641 · Severity: high · CVSS 7.8 · Published 2026-09-11

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A use-after-free vulnerability exists in the Linux kernel's CIFS file system implementation when resizing files. If the initial file resize operation fails and the system attempts a fallback operation while a network connection is being torn down or reconnected, the kernel may access memory that has already been freed, potentially leading to system crashes, data corruption, or code execution.

Technical details

The vulnerability is a use-after-free flaw in the cifs_file_set_size() function in fs/smb/client/inode.c. When cifs_file_set_size() locates a writable file handle via find_writable_file(), it borrows a CIFS tree connection (tcon) from the handle's tlink and attempts a handle-based set_file_size() RPC. If this operation fails, the code falls through to a path-based fallback that reuses the borrowed tcon. However, after calling cifsFileInfo_put() to release the handle, if that was the last reference to a tlink marked for removal (during reconnection or session teardown), cifs_put_tlink() frees the tcon. The subsequent set_path_size() call then operates on freed memory. The fix is to explicitly set tcon = NULL after cifsFileInfo_put(), which causes the existing NULL check to trigger, forcing acquisition of a fresh connection reference or clean failure if the session is unavailable.

Affected products

  • Linux Linux kernel multiple versions affected (patch applies across stable branches)

Timeline

  • 2026-09-11: disclosed: Published on NVD
  • 2026-09-07: patched: Patch committed to stable kernel tree by Greg Kroah-Hartman

References

Related threats