CVE-2026-97558
In the Linux kernel, the following vulnerability has been resolved:
smb: client: fix cifsFileInfo reference leak in deferred close
When cifs_close() defers a close, it hands the cifsFileInfo reference of the closing struct file to the queued work. Each execution of smb2_deferred_work_close() drops one such reference.
deferred_close_scheduled can be false while the work is pending: the workqueue clears PENDING when the callback starts to run, before the callback clears the flag under deferred_lock.
Leer descripción completaMostrar menos
A close in that interval requeues the running work, and the callback then clears the flag, leaving the requeued work pending with the flag down. A later cifs_open() can reuse the handle and its cifs_close() reaches the same branch: queue_delayed_work() fails because the work is still pending, but cifs_close() returns without dropping the closing file's reference. The cifsFileInfo count stays pinned and its tlink, dentry and server handle are leaked.
Check the return value and hand off the reference only when work was actually queued. Otherwise, use the shared _cifsFileInfo_put(), like the mod_delayed_work() branch above: the pending execution already owns its reference.
This issue was found by an in-house static analysis tool.
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.21%
- Percentil entre todas las CVEs puntuadas: 11
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-97558",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "c3f207ab29f793b8c942ce8067ed123f18d5b81b",
"lessThan": "a6767712902beb0f53238be485971c9a83ea1079",
"versionType": "git"
},
{
"status": "affected",
"version": "c3f207ab29f793b8c942ce8067ed123f18d5b81b",
"lessThan": "ea93759d6c2789924f4e557aed5be532207715ea",
"versionType": "git"
},
{
"status": "affected",
"version": "c3f207ab29f793b8c942ce8067ed123f18d5b81b",
"lessThan": "5520e89a5a4f834bced64cf2ac927001cc513a40",
"versionType": "git"
}
],
"programFiles": [
"fs/smb/client/file.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "5.13"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "5.13",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.18.54",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2.7",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc3",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"fs/smb/client/file.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-25T11:17:06.320",
"references": [
{
"url": "https://git.kernel.org/stable/c/5520e89a5a4f834bced64cf2ac927001cc513a40",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/a6767712902beb0f53238be485971c9a83ea1079",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/ea93759d6c2789924f4e557aed5be532207715ea",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: fix cifsFileInfo reference leak in deferred close\n\nWhen cifs_close() defers a close, it hands the cifsFileInfo reference\nof the closing struct file to the queued work. Each execution of\nsmb2_deferred_work_close() drops one such reference.\n\ndeferred_close_scheduled can be false while the work is pending: the\nworkqueue clears PENDING when the callback starts to run, before the\ncallback clears the flag under deferred_lock. A close in that\ninterval requeues the running work, and the callback then clears the\nflag, leaving the requeued work pending with the flag down. A later\ncifs_open() can reuse the handle and its cifs_close() reaches the\nsame branch: queue_delayed_work() fails because the work is still\npending, but cifs_close() returns without dropping the closing file's\nreference. The cifsFileInfo count stays pinned and its tlink, dentry\nand server handle are leaked.\n\nCheck the return value and hand off the reference only when work was\nactually queued. Otherwise, use the shared _cifsFileInfo_put(), like\nthe mod_delayed_work() branch above: the pending execution already\nowns its reference.\n\nThis issue was found by an in-house static analysis tool."
}
],
"lastModified": "2026-09-25T15:17:59.080",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}