← All Advisories

CVE-2026-98115

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-98115

Key Details

CVECVE-2026-98115
CVSS Score / Version8.8 (High) / CVSS v3.1
Updated2026-10-02
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsLinux Linux Kernel and Linux Linux
Classified asCWE-362 (Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition'))

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux Kernel
LinuxLinux
SubsystemsGeneral OT
SectorsAll Sectors

What to Know

In the Linux kernel, the following vulnerability has been resolved:

ksmbd: safely drain sessions during logoff

SMB3 multichannel allows requests for one session to run on multiple

connections. Wait for all channels bound to a session before freeing

shared session objects.

A deferred byte-range lock remains counted as a running request and only

wakes when its file closes. Wake blocked locks during the drain without

unpublishing or modifying their file objects. Synchronous CANCEL requests

must invoke their cancellation callback to wake pending operations, while

CHANGE_NOTIFY completion remains specific to the asynchronous path.

Serialize session teardown with channel registration and previous-session

cleanup, and use atomic work-state transitions so LOGOFF, CANCEL, and

connection teardown invoke cancellation callbacks only once. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-98115
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-98115