CyberRota Analysis
AI-GeneratedThe vulnerability affects the Linux kernel's SMB client implementation, specifically within the `cifs_try_adding_channels()` function, where a use-after-free condition can occur due to improper reference management. This flaw can lead to accessing freed memory, potentially resulting in system instability or exploitation by attackers. Organizations using Linux systems with SMB functionalities should prioritize patching this vulnerability to mitigate risks associated with memory corruption.
Original NVD Description
In the Linux kernel, the following vulnerability has been resolved: smb: client: Fix use-after-free in cifs_try_adding_channels() cifs_try_adding_channels() takes a temporary reference to an interface before dropping iface_lock. If cifs_ses_add_channel() fails, it drops that reference and then increments iface->weight_fulfilled. A concurrent interface list refresh can remove the list reference while channel creation is in progress. In that case, the failure-path kref_put() releases the last reference and frees iface. Updating weight_fulfilled afterward then accesses freed memory. Increment weight_fulfilled before dropping the temporary reference, keeping iface alive for the final access.