Impact
The Linux kernel contains a use‑after‑free flaw in the SMB client: when free_tgts() frees all target list entries, the ce->tgthint pointer is left pointing to a freed cache_dfs_tgt object. If later code dereferences ce->tgthint without first resetting it to NULL, the kernel dereferences invalid memory, causing memory corruption that can lead to a crash or undefined behavior. The advisory does not confirm arbitrary code execution, but a dangling kernel‑space pointer represents a critical reliability risk.
Affected Systems
The flaw exists in all Linux kernel builds that include the SMB client code and have not yet applied the patch that sets ce->tgthint to NULL after freeing the target list. No specific version ranges are supplied in the advisory.
Risk and Exploitability
The CVSS base score of 9.8 classifies this issue as critical, and the EPSS score of less than 1% indicates a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack involves sending SMB traffic that triggers the free_tgts() cleanup; however, the precise exploitation method is not detailed, so the exact feasibility remains uncertain.
OpenCVE Enrichment
Debian DSA