Back

CRITICAL

cifs: fix potential use-after-free bugs in TCP_Server_Info::hostname

Published Dec 8, 2025

Description

TCP_Server_Info::hostname may be updated once or many times during reconnect, so protect its access outside reconnect path as well and then prevent any potential use-after-free bugs.

Affected products

Remediation

Red Hat statement

This MODERATE impact use-after-free flaw in the Linux kernel's CIFS component. An attacker on an adjacent network could exploit this vulnerability during connection re-establishment, potentially leading to data integrity compromise or a denial of service.

Red Hat mitigation

To mitigate this issue, prevent the `cifs` kernel module from loading if CIFS functionality is not required. Create a file named `/etc/modprobe.d/disable-cifs.conf` with the following content: ``` install cifs /bin/true ``` This will prevent the `cifs` module from being loaded automatically. A system reboot is required for this change to take effect. Note that disabling the `cifs` module will prevent the system from mounting CIFS shares.

Metrics

Weaknesses (1)

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Linux
Published Dec 8, 2025
Updated Aug 5, 2026
Reserved Dec 8, 2025
NVD
Status Deferred
Modified Aug 4, 2026
Red Hat
Severity Moderate
Public date Dec 8, 2025