Skip to main content
HIGH

CVE-2026-98174

CVSS v3

7.5

HIGH

EPSS Score

0.2 %

exploit probability, as of 2026-10-06

CISA KEV

No

known exploited

Exploitation

—

SSVC status

Description

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix rlist race and missing initialization TCP_Server_Info.rlist is allocated via kzalloc which zeros both ->next and ->prev to NULL instead of pointing to itself, making list_empty() always return false and list_add() dereference a NULL ->prev pointer. Also, cifs_signal_cifsd_for_reconnect() can be called concurrently from multiple cifsd threads, allowing the same server's rlist node to be added twice into the lo

Technical details

CVSS v3 Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Published
2026-10-06
Last Modified
2026-10-07

Frequently asked questions

What is CVE-2026-98174?

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix rlist race and missing initialization TCP_Server_Info.rlist is allocated via kzalloc which zeros both ->next and ->prev to NULL instead of pointing to itself, making list_empty() always return false and list_add() dereference a NULL ->prev pointer. Also, cifs_signal_cifsd_for_reconnect() can be called concurrently from multiple cifsd threads, allowing the same server's rlist node to be added twice into the lo

Is CVE-2026-98174 actively exploited?

Active exploitation of CVE-2026-98174 has not been confirmed. Its EPSS score was 0.2% on 2026-10-06, the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2026-98174?

CVE-2026-98174 has a CVSS v3 base score of 7.5 (HIGH severity), with vector string CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H.

Is CVE-2026-98174 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 50 free checks/month · Free API key