CVE-2026-98174EPSS p28.4%
CVE-2026-98174CVE-2026-98174
Description
In the Linux kernel, the following vulnerability has been resolved:
smb: client: fix rlist race and missing initialization
TCP_Server_Info.rlist is allocated via kzalloc which zeros both ->next
and ->prev to NULL instead of pointing to itself, making list_empty()
always return false and list_add() dereference a NULL ->prev pointer.
Also, cifs_signal_cifsd_for_reconnect() can be called concurrently
from multiple cifsd threads, allowing the same server's rlist node to
be added twice into the local list, corrupting it.
Scoring
| CVSS | 7.5 () |
| Vector | CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H |
| EPSS | 0.36% probability of exploitation · percentile 28.4% · 2026-10-10T12:00:23Z |
| Last modified | 2026-10-07 |