Description
In the Linux kernel, the following vulnerability has been resolved:

smb: client: clear ce->tgthint in free_tgts()

When free_tgts() frees all structures in ce->tlist, ce->tgthint
is left pointing to one of the freed cache_dfs_tgt structures.

If ce->tgthint is not reset before it is used later, it results
in a use-after-free.

Set ce->tgthint to NULL in free_tgts() after the elements are
freed to reflect that no elements remain.
Published: 2026-09-11
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Use‑After‑Free in SMB client cache target list cleanup
Action: Patch Now
AI Analysis

Impact

The Linux kernel contains a use‑after‑free flaw in the SMB client: when free_tgts() frees all target list entries, the ce->tgthint pointer is left pointing to a freed cache_dfs_tgt object. If later code dereferences ce->tgthint without first resetting it to NULL, the kernel dereferences invalid memory, causing memory corruption that can lead to a crash or undefined behavior. The advisory does not confirm arbitrary code execution, but a dangling kernel‑space pointer represents a critical reliability risk.

Affected Systems

The flaw exists in all Linux kernel builds that include the SMB client code and have not yet applied the patch that sets ce->tgthint to NULL after freeing the target list. No specific version ranges are supplied in the advisory.

Risk and Exploitability

The CVSS base score of 9.8 classifies this issue as critical, and the EPSS score of less than 1% indicates a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack involves sending SMB traffic that triggers the free_tgts() cleanup; however, the precise exploitation method is not detailed, so the exact feasibility remains uncertain.

Generated by OpenCVE AI on September 15, 2026 at 22:03 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the kernel patch that nullifies ce->tgthint after freeing the target list.
  • Disable the SMB client feature or block SMB traffic on ports 445/TCP and 445/UDP in the firewall if a patch is not yet available.
  • Monitor kernel logs for fatal errors related to the SMB client and set up alerts for abnormal SMB traffic patterns to detect potential exploitation attempts.

Generated by OpenCVE AI on September 15, 2026 at 22:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 14 Sep 2026 12:30:00 +0000


Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H'}

cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-825
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H'}

threat_severity

Important


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: smb: client: clear ce->tgthint in free_tgts() When free_tgts() frees all structures in ce->tlist, ce->tgthint is left pointing to one of the freed cache_dfs_tgt structures. If ce->tgthint is not reset before it is used later, it results in a use-after-free. Set ce->tgthint to NULL in free_tgts() after the elements are freed to reflect that no elements remain.
Title smb: client: clear ce->tgthint in free_tgts()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-14T12:01:41.762Z

Reserved: 2026-09-11T19:38:34.739Z

Link: CVE-2026-89636

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:49.243

Modified: 2026-09-14T13:19:16.797

Link: CVE-2026-89636

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-11T19:45:30Z

Links: CVE-2026-89636 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T22:15:17Z

Weaknesses
  • CWE-825

    Expired Pointer Dereference