{"id":"CVE-2026-98172","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: fix smbd_connection leak on cifs_get_tcp_session() error\n\nWhen an RDMA connection is successfully established via\nsmbd_get_connection() but cifs_get_tcp_se…","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: fix smbd_connection leak on cifs_get_tcp_session() error\n\nWhen an RDMA connection is successfully established via\nsmbd_get_connection() but cifs_get_tcp_se…","severity":"none","vendor":"Linux","product":"Linux","affected":["Linux >= 2f8946464b11822169b9f10c7cf58a2440b51d54 < 3164402c58940ff58a3cecdb026405f07b0253af","Linux >= 2f8946464b11822169b9f10c7cf58a2440b51d54 < e3344bb0ff5ec8a276f42239e140f5442841ef23","Linux >= 2f8946464b11822169b9f10c7cf58a2440b51d54 < 5c908e49d349266dff0c86dda6a05df0ff19b824","Linux >= 2f8946464b11822169b9f10c7cf58a2440b51d54 < 928edc4bd6a617caabeb575fc13c254d9df623c4","Linux >= 2f8946464b11822169b9f10c7cf58a2440b51d54 < b26a3fcf2f1c2cadba400290b639f01395db8fc8","Linux >= 2f8946464b11822169b9f10c7cf58a2440b51d54 < e75c96157d45e498970158c8f7373d90102e33b9","Linux 4.16"],"published":"2026-10-06","updated":"2026-10-06","sourceUpdated":"2026-10-06T09:17:58.920","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-98172","references":[{"url":"https://git.kernel.org/stable/c/3164402c58940ff58a3cecdb026405f07b0253af","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5c908e49d349266dff0c86dda6a05df0ff19b824","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/928edc4bd6a617caabeb575fc13c254d9df623c4","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b26a3fcf2f1c2cadba400290b639f01395db8fc8","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e3344bb0ff5ec8a276f42239e140f5442841ef23","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e75c96157d45e498970158c8f7373d90102e33b9","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-06T08:50:17.456Z","slug":"CVE-2026-98172","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: fix smbd_connection leak on cifs_get_tcp_session() error\n\nWhen an RDMA connection is successfully established via\nsmbd_get_connection() but cifs_get_tcp_session() later fails (e.g.\nkthread_create() returns an error), the error path frees tcp_ses\nwithout first destroying the smbd_connection.\n\nFix this by calling smbd_destroy() in the out_err cleanup path before\nkfree(tcp_ses).  smbd_destroy() safely handles the case where\nsmbd_conn is NULL, so it can be called unconditionally.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}