Linux Kernel SMB3 Multichannel Session Management Vulnerability
CVE-2026-98115

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
25 September 2026

What is CVE-2026-98115?

A vulnerability within the Linux kernel's SMB3 multichannel feature could lead to session management issues during logoff. This flaw allows multiple connections to run requests for a single session, potentially disrupting session termination processes. Specifically, deferred byte-range locks may incorrectly remain active, causing complications when closing associated files and managing session teardown. Mitigation steps involve ensuring proper synchronization during session and connection cleanup, employing atomic work-state transitions, and ensuring that cancellation requests are correctly handled.

Affected Version(s)

Linux 76e98a158b207771a6c9a0de0a60522a446a3447

Linux 76e98a158b207771a6c9a0de0a60522a446a3447

Linux 118fd997612d1efc94a86c307c6c6d659ebe29fc

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.