Bug 2541214 (CVE-2026-97557) - CVE-2026-97557 kernel: smb: client: avoid leaking refcount in cifs_queue_oplock_break()
Summary: CVE-2026-97557 kernel: smb: client: avoid leaking refcount in cifs_queue_oplo...
Keywords:
Status: NEW
Alias: CVE-2026-97557
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-25 11:03 UTC by OSIDB Bzimport
Modified: 2026-09-29 02:33 UTC (History)
17 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-09-25 11:03:27 UTC
In the Linux kernel, the following vulnerability has been resolved:

smb: client: avoid leaking refcount in cifs_queue_oplock_break()

cifs_queue_oplock_break() unconditionally takes a reference on the
target file before queueing cifs_oplock_break(). Only that work item
decreases the reference counter again.

If another oplock break arrives while that work is still queued,
queue_work() will return false and not queue this second work item. As a
result, we will never reach the point to drop the file reference again
and are leaking this reference. This can be triggered when interacting
with a slow-responding server.

As a result, later unmount operations for this file system will fail with

  BUG: Dentry ... still in use (1) [unmount of cifs cifs]
  VFS: Busy inodes after unmount of cifs (cifs)
  kernel BUG at fs/super.c:777!

Fix this by only incrementing the reference count if the work has been
queued successfully. Taking it after queue_work() is safe because all
three callers hold tcon->open_file_lock across the call and
_cifsFileInfo_put() decrements under that same lock, so a worker that
starts the handler in the window cannot drop the reference before it has
been taken.


Note You need to log in before you can comment on or make changes to this bug.