smb: client: avoid leaking refcount in cifs_queue_oplock_break()
Summary
| CVE | CVE-2026-97557 |
|---|---|
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-25 11:17:06 UTC |
| Updated | 2026-09-25 15:17:58 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved: smb: client: avoid leaking refcount in cifs_queue_oplock_break() cifs_queue_oplock_break() unconditionally takes a reference on the target file before queueing cifs_oplock_break(). Only that work item decreases the reference counter again. If another oplock break arrives while that work is still queued, queue_work() will return false and not queue this second work item. As a result, we will never reach the point to drop the file reference again and are leaking this reference. This can be triggered when interacting with a slow-responding server. As a result, later unmount operations for this file system will fail with BUG: Dentry ... still in use (1) [unmount of cifs cifs] VFS: Busy inodes after unmount of cifs (cifs) kernel BUG at fs/super.c:777! Fix this by only incrementing the reference count if the work has been queued successfully. Taking it after queue_work() is safe because all three callers hold tcon->open_file_lock across the call and _cifsFileInfo_put() decrements under that same lock, so a worker that starts the handler in the window cannot drop the reference before it has been taken. |
Risk And Classification
Primary CVSS: v3.1 7.5 HIGH from 416baaa9-dc9f-4396-8d5f-8c081fb06d67
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS: 0.006030000 probability, percentile 0.467380000 (date 2026-09-27)
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | Secondary | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
| 3.1 | CNA | DECLARED | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
NoneIntegrity
NoneAvailability
HighCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Linux | affected b98749cac4a695f084a5ff076f4510b23e353ecd af0193bbf1ac8c0f67f972998b0cc629d6116cf6 git | Not specified |
| CNA | Linux | Linux | affected b98749cac4a695f084a5ff076f4510b23e353ecd 2ed2c29dd9593637cfa25ac1eb23241b20202778 git | Not specified |
| CNA | Linux | Linux | affected b98749cac4a695f084a5ff076f4510b23e353ecd dfe7b750c7e069873a8a57a11c816831a235618a git | Not specified |
| CNA | Linux | Linux | affected b98749cac4a695f084a5ff076f4510b23e353ecd 9f2e63f1b2d5fc5b5423424902c091123e220e7e git | Not specified |
| CNA | Linux | Linux | affected 2429fcf06d3cb962693868ab0a927c9038f12a2d git | Not specified |
| CNA | Linux | Linux | affected 1ee4f2d7cdcd4508cc3cbe3b2622d7177b89da12 git | Not specified |
| CNA | Linux | Linux | affected 53fc31a4853e30d6e8f142b824f724da27ff3e40 git | Not specified |
| CNA | Linux | Linux | affected 8092ecc306d81186a64cda42411121f4d35aaff4 git | Not specified |
| CNA | Linux | Linux | affected ebac4d0adf68f8962bd82fcf483936edd6ec095b git | Not specified |
| CNA | Linux | Linux | affected 3.16.72 3.17 semver | Not specified |
| CNA | Linux | Linux | affected 4.9.171 4.10 semver | Not specified |
| CNA | Linux | Linux | affected 4.14.114 4.15 semver | Not specified |
| CNA | Linux | Linux | affected 4.19.37 4.20 semver | Not specified |
| CNA | Linux | Linux | affected 5.0.10 5.1 semver | Not specified |
| CNA | Linux | Linux | affected 5.1 | Not specified |
| CNA | Linux | Linux | unaffected 5.1 semver | Not specified |
| CNA | Linux | Linux | unaffected 6.12.111 6.12.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.18.53 6.18.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.2.7 7.2.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.3-rc3 * original_commit_for_fix | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| git.kernel.org/stable/c/af0193bbf1ac8c0f67f972998b0cc629d6116cf6 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/2ed2c29dd9593637cfa25ac1eb23241b20202778 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/9f2e63f1b2d5fc5b5423424902c091123e220e7e | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/dfe7b750c7e069873a8a57a11c816831a235618a | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.