From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id A09B958E2D4 for ; Fri, 11 Sep 2026 19:59:55 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789156802; cv=none; b=IejMm+9NChMNzFoCFCZa6G6/DOY35S4JblqZxA4biWi7CNoaWaU8bk6epTXwWo5PWJ2QBatIbNAP1BkLpk9ZA7c96lozg6ael0z8shT2dzYzORJ2/XcwyYv2sWj76mkt45EKv/kpP68EqpDNlz3HzrVoP4GxuWCTJNrrKJeuTvw= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789156802; c=relaxed/simple; bh=tal+8efc9Cayfpv5SlqS6Y+kQjd2Vw2N1y7qBiidP8g=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=EpHUZZX8jSRGZHb9Nokc71gdO3M+Lj4+dJp3n2Q8g+Z9G6qcsOi1a5pSTPFniyNwkEhxgQYgQs2ljI3nDz1O6VJSE8kyrzZirVnE75q6VqT0LS6X6WcVKDEL9mBulw5RDhE30uwSovC1lS/+wSBekhGqUl+11/C4K3Bkznr8gNg= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=1k33aVOE; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="1k33aVOE" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 822781F00893; Fri, 11 Sep 2026 19:59:52 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1789156793; bh=4RZ+xTK9uKPQIvRI3mNFuJFaL+F9l8o/S8ybcP+UqgA=; h=From:To:Cc:Subject:Date:Reply-To; b=1k33aVOEUNtOLbm3HcB6qJtLWaSuk6lx1yfzENYeE4qYV/2xF9nXDo9i9l/gN0XD6 eWrL4kZaCJzYqqfIMv9itQtTm/f88K48b3tVrvWSIOR9cXYAbOHM9FcDPy+ZxJMYL6 3Rx2aa8M/rkOK+uZVTjI93bWCBvJ2cYCwHIdFdNY= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-89636: smb: client: clear ce->tgthint in free_tgts() Date: Fri, 11 Sep 2026 21:45:25 +0200 Message-ID: <2026091140-CVE-2026-89636-c510@gregkh> X-Mailer: git-send-email 2.55.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=2535; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=ipQFGpAxgCuLUmBROPkabc2gnBbaZAE6hT65R5d8zys=; b=owGbwMvMwCRo6H6F97bub03G02pJDFlLIktPZrKGHNnTU/NwYfb52orI26Zir97Waedtk1CQK bkktp2tI5aFQZCJQVZMkeXLNp6j+ysOKXoZ2p6GmcPKBDKEgYtTACYS9YdhwcFPfFMLO158fOd5 8Vt1wtZ7yoV5WQwLpsvKb36wYe7v5e1NU43TGZZnvjL7BgA= X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: smb: client: clear ce->tgthint in free_tgts() When free_tgts() frees all structures in ce->tlist, ce->tgthint is left pointing to one of the freed cache_dfs_tgt structures. If ce->tgthint is not reset before it is used later, it results in a use-after-free. Set ce->tgthint to NULL in free_tgts() after the elements are freed to reflect that no elements remain. The Linux kernel CVE team has assigned CVE-2026-89636 to this issue. Affected and fixed versions =========================== Issue introduced in 5.0 with commit 54be1f6c1c37498bba557049df646cc239fa37e3 and fixed in 6.12.109 with commit 7507bd1885643d0461a6017767492450af1ce2a3 Issue introduced in 5.0 with commit 54be1f6c1c37498bba557049df646cc239fa37e3 and fixed in 6.18.50 with commit 9ab46a13798a61d9d020b01d4e57efdabe6624fa Issue introduced in 5.0 with commit 54be1f6c1c37498bba557049df646cc239fa37e3 and fixed in 7.2.4 with commit 5baab40404a9393bcc0b7b8f1950bf2c307e0984 Issue introduced in 5.0 with commit 54be1f6c1c37498bba557049df646cc239fa37e3 and fixed in 7.3-rc1 with commit b1b741cf8e7ce1b91d937e23decd3d3358748700 Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-89636 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: fs/smb/client/dfs_cache.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/7507bd1885643d0461a6017767492450af1ce2a3 https://git.kernel.org/stable/c/9ab46a13798a61d9d020b01d4e57efdabe6624fa https://git.kernel.org/stable/c/5baab40404a9393bcc0b7b8f1950bf2c307e0984 https://git.kernel.org/stable/c/b1b741cf8e7ce1b91d937e23decd3d3358748700