{"id":"CVE-2026-98261","title":"In the Linux kernel, the following vulnerability has been resolved:\n\ncifs: Fix server use-after-free in cifs_chan_skip_or_disable()\n\nWhen a secondary channel is no longer supported by the server,\ncifs_chan_skip_or_disable() drops the cha…","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\ncifs: Fix server use-after-free in cifs_chan_skip_or_disable()\n\nWhen a secondary channel is no longer supported by the server,\ncifs_chan_skip_or_disable() drops the cha…","severity":"none","vendor":"Linux","product":"Linux","affected":["Linux >= 50e8363ecc85da49764781da90ebffe1a657b370 < 0338489960ddad6368bce55e8adbc176c523093d","Linux >= f591062bdbf4742b7f1622173017f19e927057b0 < edd52eae5fcfb8433b6bb0e7cd98db438fe01227","Linux >= f591062bdbf4742b7f1622173017f19e927057b0 < fcc0a935bb6e37ecbf7e4335061309f896f35780","Linux >= f591062bdbf4742b7f1622173017f19e927057b0 < 7a1b27780b113583a94256d58dabfe7c0d9286e7","Linux >= f591062bdbf4742b7f1622173017f19e927057b0 < 717e0a25036b6c92cecace30913b2d874a4c22b8","Linux d61ba1d71ea6039eca7ada870bf3f0c3c8fc12e4","Linux >= 6.6.15 < 6.6.158","Linux >= 6.7.3 < 6.8","Linux 6.8"],"published":"2026-10-06","updated":"2026-10-06","sourceUpdated":"2026-10-06T09:18:15.200","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-98261","references":[{"url":"https://git.kernel.org/stable/c/0338489960ddad6368bce55e8adbc176c523093d","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/717e0a25036b6c92cecace30913b2d874a4c22b8","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7a1b27780b113583a94256d58dabfe7c0d9286e7","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/edd52eae5fcfb8433b6bb0e7cd98db438fe01227","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fcc0a935bb6e37ecbf7e4335061309f896f35780","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-06T08:50:17.427Z","slug":"CVE-2026-98261","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\ncifs: Fix server use-after-free in cifs_chan_skip_or_disable()\n\nWhen a secondary channel is no longer supported by the server,\ncifs_chan_skip_or_disable() drops the channel reference with\ncifs_put_tcp_session() and then continues to use the server pointer by\ncalling cifs_signal_cifsd_for_reconnect() on it and reading its\nprimary_server pointer. cifs_put_tcp_session() can drop the last\nreference of the channel and tear it down, so both the channel and the\nprimary server (whose reference is also dropped by\ncifs_put_tcp_session()) can be freed before they are signaled for\nreconnect.\n\nSignal the channel and the primary server and capture the primary\nserver pointer before dropping the channel reference with\ncifs_put_tcp_session().\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}