smb: client: Fix refcount leak for cifs_sb_tlink
Summary
| CVE | CVE-2025-40103 |
|---|---|
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2025-10-30 10:15:34 UTC |
| Updated | 2026-04-18 09:16:12 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved: smb: client: Fix refcount leak for cifs_sb_tlink Fix three refcount inconsistency issues related to `cifs_sb_tlink`. Comments for `cifs_sb_tlink` state that `cifs_put_tlink()` needs to be called after successful calls to `cifs_sb_tlink()`. Three calls fail to update refcount accordingly, leading to possible resource leaks. |
Risk And Classification
EPSS: 0.000760000 probability, percentile 0.227680000 (date 2026-04-21)
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Linux | affected 8ceb984379462f94bdebef3288d569c6e1f912ea d3c8ea197055c260119a13360e8202a27e53e1e4 git | Not specified |
| CNA | Linux | Linux | affected 8ceb984379462f94bdebef3288d569c6e1f912ea 790282abe9d805f08618c1c24ea2529e7259b692 git | Not specified |
| CNA | Linux | Linux | affected 8ceb984379462f94bdebef3288d569c6e1f912ea d7dd034c14928306db1b46be277ae439b84dacf9 git | Not specified |
| CNA | Linux | Linux | affected 8ceb984379462f94bdebef3288d569c6e1f912ea e15605b68b490186da2ad8029c0351a9cfb0b9af git | Not specified |
| CNA | Linux | Linux | affected 8ceb984379462f94bdebef3288d569c6e1f912ea 896bb31e1416f582503db1350cf1bd10dc64e5a6 git | Not specified |
| CNA | Linux | Linux | affected 8ceb984379462f94bdebef3288d569c6e1f912ea c2b77f42205ef485a647f62082c442c1cd69d3fc git | Not specified |
| CNA | Linux | Linux | affected 3.7 | Not specified |
| CNA | Linux | Linux | unaffected 3.7 semver | Not specified |
| CNA | Linux | Linux | unaffected 5.15.203 5.15.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.1.158 6.1.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.6.114 6.6.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.12.55 6.12.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.17.5 6.17.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.18 * original_commit_for_fix | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| git.kernel.org/stable/c/e15605b68b490186da2ad8029c0351a9cfb0b9af | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/790282abe9d805f08618c1c24ea2529e7259b692 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/896bb31e1416f582503db1350cf1bd10dc64e5a6 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/c2b77f42205ef485a647f62082c442c1cd69d3fc | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/d7dd034c14928306db1b46be277ae439b84dacf9 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/d3c8ea197055c260119a13360e8202a27e53e1e4 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.