CVE-2026-89636

In the Linux kernel, the following vulnerability has been resolved: smb: client: clear ce->tgthint in free_tgts() When free_tgts() frees all structures in ce->tlist, ce->tgthint is left pointing to one of the freed cache_dfs_tgt structures. If ce->tgthint is not reset before it is used later, it results in a use-after-free. Set ce->tgthint to NULL in free_tgts() after the elements are freed to reflect that no elements remain.

  • Published Sep 11, 2026
  • CVSS 9.8 critical
  • 0.7% chance of exploitation in the next 30 days (EPSS)
  • A fix is available

Affected software

In the news

CVE-2026-89636 at the National Vulnerability Database