---
id: CVE-2026-98175
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  smb: client: cancel reconnect work in clean_demultiplex_info()

  clean_demultiplex_info() cancels server->echo delayed work but not
  server->reconnect, which can cause a …
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  smb: client: cancel reconnect work in clean_demultiplex_info()

  clean_demultiplex_info() cancels server->echo delayed work but not
  server->reconnect, which can cause a …
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= 53e0e11efe9289535b060a51d4cf37c25e0d0f2b <
    180380272f116dbd2b0354c5c7872e112e519149
  - >-
    Linux >= 53e0e11efe9289535b060a51d4cf37c25e0d0f2b <
    e3f6a779433d13aafb5edab59e4f9313051e8a52
  - >-
    Linux >= 53e0e11efe9289535b060a51d4cf37c25e0d0f2b <
    7ab9ceedd860216fb97f2d8574cbe58b8906f42a
  - >-
    Linux >= 53e0e11efe9289535b060a51d4cf37c25e0d0f2b <
    2e5103e11a17c274715dd56cf185eeedccf686b8
  - >-
    Linux >= 53e0e11efe9289535b060a51d4cf37c25e0d0f2b <
    c65eae6f61d1778ff7a82e4aae4080e26f486af1
  - Linux e008a962311a875a828cbae54b43285858aaa6c8
  - Linux 123b228a09b90b50b0a9d6eb8294cf0c42efc029
  - Linux 0ba4c6eaaacbcc4b18f51bb3b1567c65a8fecca9
  - Linux d0d2a4c82942e2f51e4984beea1f7e5a994bd06c
  - Linux 15a12fbbf365a483b1c19f9caeb707b3bea77e10
  - Linux f0b715409cb9cf7e21e690f9b163047739761962
  - Linux ff04da387c10b6bf7b510392742c8cd46c130fd6
  - Linux 48f9526f4dcb4b132fe0dc2450835311e3b013a6
  - Linux >= 3.10.107 < 3.11
  - Linux >= 3.12.70 < 3.13
  - Linux >= 3.16.42 < 3.17
  - Linux >= 3.18.47 < 3.19
  - Linux >= 4.1.38 < 4.2
  - Linux >= 4.4.40 < 4.5
  - Linux >= 4.8.16 < 4.9
  - Linux >= 4.9.1 < 4.10
  - Linux 4.10
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T09:17:59.477'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-98175'
references:
  - url: 'https://git.kernel.org/stable/c/180380272f116dbd2b0354c5c7872e112e519149'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/2e5103e11a17c274715dd56cf185eeedccf686b8'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/7ab9ceedd860216fb97f2d8574cbe58b8906f42a'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/c65eae6f61d1778ff7a82e4aae4080e26f486af1'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/e3f6a779433d13aafb5edab59e4f9313051e8a52'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-06T08:50:17.453Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

smb: client: cancel reconnect work in clean_demultiplex_info()

clean_demultiplex_info() cancels server->echo delayed work but not
server->reconnect, which can cause a use-after-free when the
demultiplex thread exits while a reconnect work is still queued:

  cifs_demultiplex_thread()
    cifs_readv_from_socket()
      cifs_reconnect()
        __cifs_reconnect()
          cifs_queue_server_reconn()
            mod_delayed_work(cifsiod_wq, &server->reconnect, 0)
    clean_demultiplex_info()
      cancel_delayed_work_sync(&server->echo)   // echo canceled
                                                 // reconnect NOT canceled
      kfree_sensitive(server)                    // server freed

  ...later, on cifsiod_wq:

  smb2_reconnect_server()
    server->srv_count  // UAF read of freed server

Fix this by canceling server->reconnect delayed work in
clean_demultiplex_info() before the server is freed, the same way
cifs_put_tcp_session() already does.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
