CVE-2026-98174
HighIn the Linux kernel, the following vulnerability has been resolved: smb: client: fix rlist race and missing initialization TCP_Server_Info.rlist is allocated via kzalloc which zeros both ->next and ->prev to NULL instead of pointing to itself, making list_empty() always return false and list_add() dereference a NULL ->prev pointer. Also, cifs_signal_cifsd_for_reconnect() can be called concurrently from multiple cifsd threads, allowing the same server's rlist node to be added twice into the local list, corrupting it.
CVSS 3.1 score
7.5
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected versions
Fixed in
6.6.158,
6.12.112,
6.18.54,
7.2.8,
7.3-rc4
and their respective stable series.
References
5 totalFrequently asked questions
-
What is CVE-2026-98174?
CVE-2026-98174 is a High severity Linux kernel vulnerability with a CVSS score of 7.5 out of 10 . CVE-2026-98174 has not been confirmed as actively exploited and is not listed in the CISA KEV catalog.
-
What is the CVSS score for CVE-2026-98174?
CVE-2026-98174 has a CVSS score of 7.5 out of 10, rated High severity (CVSS 3.1). The vector string is
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H. -
Is there a patch available for CVE-2026-98174?
Yes. CVE-2026-98174 has been patched. Fixed versions include 6.6.158, 6.12.112, 6.18.54 and others.
-
Is CVE-2026-98174 actively exploited?
No. CVE-2026-98174 has not been confirmed as actively exploited. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.