CVE-2026-98174: Linux

High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix rlist race and missing initialization TCP_Server_Info.rlist is allocated via kzalloc which zeros both ->next and ->prev to NULL instead of pointing to itself, making list_empty() always return false and list_add() dereference a NULL ->prev pointer. Also, cifs_signal_cifsd_for_reconnect() can be called concurrently from multiple cifsd threads, allowing the same server's rlist node to be added twice into the local list, corrupting it.

Affected products

  • Linux Linux: before 6.6.158 (fixed in 6.6.158); before 6.12.112 (fixed in 6.12.112); before 6.18.54 (fixed in 6.18.54); before 7.2.8 (fixed in 7.2.8); from 6.7, before 6.12.112 (fixed in 6.12.112); from 6.13, before 6.18.54 (fixed in 6.18.54); …

Published 2026-10-06. Last modified 2026-10-07.