---
id: CVE-2026-98261
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  cifs: Fix server use-after-free in cifs_chan_skip_or_disable()

  When a secondary channel is no longer supported by the server,
  cifs_chan_skip_or_disable() drops the cha…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  cifs: Fix server use-after-free in cifs_chan_skip_or_disable()

  When a secondary channel is no longer supported by the server,
  cifs_chan_skip_or_disable() drops the cha…
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= 50e8363ecc85da49764781da90ebffe1a657b370 <
    0338489960ddad6368bce55e8adbc176c523093d
  - >-
    Linux >= f591062bdbf4742b7f1622173017f19e927057b0 <
    edd52eae5fcfb8433b6bb0e7cd98db438fe01227
  - >-
    Linux >= f591062bdbf4742b7f1622173017f19e927057b0 <
    fcc0a935bb6e37ecbf7e4335061309f896f35780
  - >-
    Linux >= f591062bdbf4742b7f1622173017f19e927057b0 <
    7a1b27780b113583a94256d58dabfe7c0d9286e7
  - >-
    Linux >= f591062bdbf4742b7f1622173017f19e927057b0 <
    717e0a25036b6c92cecace30913b2d874a4c22b8
  - Linux d61ba1d71ea6039eca7ada870bf3f0c3c8fc12e4
  - Linux >= 6.6.15 < 6.6.158
  - Linux >= 6.7.3 < 6.8
  - Linux 6.8
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T09:18:15.200'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-98261'
references:
  - url: 'https://git.kernel.org/stable/c/0338489960ddad6368bce55e8adbc176c523093d'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/717e0a25036b6c92cecace30913b2d874a4c22b8'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/7a1b27780b113583a94256d58dabfe7c0d9286e7'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/edd52eae5fcfb8433b6bb0e7cd98db438fe01227'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/fcc0a935bb6e37ecbf7e4335061309f896f35780'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-06T08:50:17.427Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

cifs: Fix server use-after-free in cifs_chan_skip_or_disable()

When a secondary channel is no longer supported by the server,
cifs_chan_skip_or_disable() drops the channel reference with
cifs_put_tcp_session() and then continues to use the server pointer by
calling cifs_signal_cifsd_for_reconnect() on it and reading its
primary_server pointer. cifs_put_tcp_session() can drop the last
reference of the channel and tear it down, so both the channel and the
primary server (whose reference is also dropped by
cifs_put_tcp_session()) can be freed before they are signaled for
reconnect.

Signal the channel and the primary server and capture the primary
server pointer before dropping the channel reference with
cifs_put_tcp_session().

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
