CVE-2026-97557
In the Linux kernel, the following vulnerability has been resolved:
smb: client: avoid leaking refcount in cifs_queue_oplock_break()
cifs_queue_oplock_break() unconditionally takes a reference on the target file before queueing cifs_oplock_break(). Only that work item decreases the reference counter again.
If another oplock break arrives while that work is still queued, queue_work() will return false and not queue this second work item. As a result, we will never reach the point to drop the file reference again and are leaking this reference. This can be triggered when interacting with a slow-responding server.
Leer descripción completaMostrar menos
As a result, later unmount operations for this file system will fail with
Fix this by only incrementing the reference count if the work has been queued successfully. Taking it after queue_work() is safe because all three callers hold tcon->open_file_lock across the call and _cifsFileInfo_put() decrements under that same lock, so a worker that starts the handler in the window cannot drop the reference before it has been taken.
Detalles técnicos trazas, registros y código del informe original
BUG: Dentry ... still in use (1) [unmount of cifs cifs] VFS: Busy inodes after unmount of cifs (cifs) kernel BUG at fs/super.c:777!
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.66%
- Percentil entre todas las CVEs puntuadas: 50
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1190Exploit Public-Facing Applicationinitial access60 % - Impacto principal
T1499Endpoint Denial of Serviceimpact55 %
Inferido por reglas deterministas a partir del vector CVSS y la CWE. Solo orientativo.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/2ed2c29dd9593637cfa25ac1eb23241b20202778
- https://git.kernel.org/stable/c/735a3a610136ae10f381d0909dff38e5b5c5f056
- https://git.kernel.org/stable/c/9f2e63f1b2d5fc5b5423424902c091123e220e7e
- https://git.kernel.org/stable/c/af0193bbf1ac8c0f67f972998b0cc629d6116cf6
- https://git.kernel.org/stable/c/de2a6bcff2659bea40c7485115b57f0ae189fc01
- https://git.kernel.org/stable/c/dfe7b750c7e069873a8a57a11c816831a235618a
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-97557",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Secondary",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "b98749cac4a695f084a5ff076f4510b23e353ecd",
"lessThan": "735a3a610136ae10f381d0909dff38e5b5c5f056",
"versionType": "git"
},
{
"status": "affected",
"version": "b98749cac4a695f084a5ff076f4510b23e353ecd",
"lessThan": "de2a6bcff2659bea40c7485115b57f0ae189fc01",
"versionType": "git"
},
{
"status": "affected",
"version": "b98749cac4a695f084a5ff076f4510b23e353ecd",
"lessThan": "af0193bbf1ac8c0f67f972998b0cc629d6116cf6",
"versionType": "git"
},
{
"status": "affected",
"version": "b98749cac4a695f084a5ff076f4510b23e353ecd",
"lessThan": "2ed2c29dd9593637cfa25ac1eb23241b20202778",
"versionType": "git"
},
{
"status": "affected",
"version": "b98749cac4a695f084a5ff076f4510b23e353ecd",
"lessThan": "dfe7b750c7e069873a8a57a11c816831a235618a",
"versionType": "git"
},
{
"status": "affected",
"version": "b98749cac4a695f084a5ff076f4510b23e353ecd",
"lessThan": "9f2e63f1b2d5fc5b5423424902c091123e220e7e",
"versionType": "git"
},
{
"status": "affected",
"version": "2429fcf06d3cb962693868ab0a927c9038f12a2d",
"versionType": "git"
},
{
"status": "affected",
"version": "1ee4f2d7cdcd4508cc3cbe3b2622d7177b89da12",
"versionType": "git"
},
{
"status": "affected",
"version": "53fc31a4853e30d6e8f142b824f724da27ff3e40",
"versionType": "git"
},
{
"status": "affected",
"version": "8092ecc306d81186a64cda42411121f4d35aaff4",
"versionType": "git"
},
{
"status": "affected",
"version": "ebac4d0adf68f8962bd82fcf483936edd6ec095b",
"versionType": "git"
},
{
"status": "affected",
"version": "3.16.72",
"lessThan": "3.17",
"versionType": "semver"
},
{
"status": "affected",
"version": "4.9.171",
"lessThan": "4.10",
"versionType": "semver"
},
{
"status": "affected",
"version": "4.14.114",
"lessThan": "4.15",
"versionType": "semver"
},
{
"status": "affected",
"version": "4.19.37",
"lessThan": "4.20",
"versionType": "semver"
},
{
"status": "affected",
"version": "5.0.10",
"lessThan": "5.1",
"versionType": "semver"
}
],
"programFiles": [
"fs/smb/client/misc.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "5.1"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "5.1",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.1.189",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.158",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.111",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.53",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2.7",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc3",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"fs/smb/client/misc.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-25T11:17:06.193",
"references": [
{
"url": "https://git.kernel.org/stable/c/2ed2c29dd9593637cfa25ac1eb23241b20202778",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/735a3a610136ae10f381d0909dff38e5b5c5f056",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/9f2e63f1b2d5fc5b5423424902c091123e220e7e",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/af0193bbf1ac8c0f67f972998b0cc629d6116cf6",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/de2a6bcff2659bea40c7485115b57f0ae189fc01",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/dfe7b750c7e069873a8a57a11c816831a235618a",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: avoid leaking refcount in cifs_queue_oplock_break()\n\ncifs_queue_oplock_break() unconditionally takes a reference on the\ntarget file before queueing cifs_oplock_break(). Only that work item\ndecreases the reference counter again.\n\nIf another oplock break arrives while that work is still queued,\nqueue_work() will return false and not queue this second work item. As a\nresult, we will never reach the point to drop the file reference again\nand are leaking this reference. This can be triggered when interacting\nwith a slow-responding server.\n\nAs a result, later unmount operations for this file system will fail with\n\n BUG: Dentry ... still in use (1) [unmount of cifs cifs]\n VFS: Busy inodes after unmount of cifs (cifs)\n kernel BUG at fs/super.c:777!\n\nFix this by only incrementing the reference count if the work has been\nqueued successfully. Taking it after queue_work() is safe because all\nthree callers hold tcon->open_file_lock across the call and\n_cifsFileInfo_put() decrements under that same lock, so a worker that\nstarts the handler in the window cannot drop the reference before it has\nbeen taken."
}
],
"lastModified": "2026-10-03T11:18:03.447",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}