Linux Kernel SMB3 Multichannel Session Management Vulnerability
CVE-2026-98115
Currently unrated
What is CVE-2026-98115?
A vulnerability within the Linux kernel's SMB3 multichannel feature could lead to session management issues during logoff. This flaw allows multiple connections to run requests for a single session, potentially disrupting session termination processes. Specifically, deferred byte-range locks may incorrectly remain active, causing complications when closing associated files and managing session teardown. Mitigation steps involve ensuring proper synchronization during session and connection cleanup, employing atomic work-state transitions, and ensuring that cancellation requests are correctly handled.
Affected Version(s)
Linux 76e98a158b207771a6c9a0de0a60522a446a3447
Linux 76e98a158b207771a6c9a0de0a60522a446a3447
Linux 118fd997612d1efc94a86c307c6c6d659ebe29fc