OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-98112

HIGH · CVSS 7.8 EPSS 0.12%

Source: NVD + CISA KEV + EPSS · Published 2026-09-25 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

A vulnerability in the Linux kernel's ksmbd component affects the listener thread's lifecycle management, specifically during netdevice events. This flaw can lead to premature termination of the listener thread, potentially causing instability or denial of service in systems relying on SMB networking. Linux administrators and developers should prioritize this issue to ensure the stability and reliability of their SMB implementations.

CVE
CVE-2026-98112
Severity
HIGH
CVSS
7.8
EPSS
0.12%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix listener task lifetime on netdev events The listener thread exits when its listening socket is shutdown. The netdevice notifier shuts down the socket before calling kthread_stop(), so the task_struct can be freed before kthread_stop() gets its reference. Create the listener in a stopped state and hold an extra task_struct reference until kthread_stop_put() completes. Also stop and release listeners before freeing their interface records during TCP teardown.