← All Advisories

CVE-2026-98174

Last refreshed2026-10-09

Status: UPDATED  |  Advisory ID: CVE-2026-98174

Key Details

CVECVE-2026-98174
CVSS Score / Version7.5 (High) / CVSS v3.1
Updated2026-10-07
CVSS VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS Proseattack vector is network; attack complexity is high; privileges required is none; user interaction is required; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsLinux Kernel

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux Kernel
SubsystemsOT Supporting Infrastructure
SectorsAll Sectors

What to Know

In the Linux kernel, the following vulnerability has been resolved:

smb: client: fix rlist race and missing initialization

TCP_Server_Info.rlist is allocated via kzalloc which zeros both ->next

and ->prev to NULL instead of pointing to itself, making list_empty()

always return false and list_add() dereference a NULL ->prev pointer.

Also, cifs_signal_cifsd_for_reconnect() can be called concurrently

from multiple cifsd threads, allowing the same server's rlist node to

be added twice into the local list, corrupting it. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-98174
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-98174