OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-97557

HIGH · CVSS 7.5 EPSS 0.66%

Source: NVD + CISA KEV + EPSS · Published 2026-09-25 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's CIFS (Common Internet File System) implementation, specifically in the `cifs_queue_oplock_break()` function, which improperly manages reference counting for file objects. This oversight can lead to a reference leak when multiple oplock break requests are queued, causing unmount operations to fail and potentially resulting in system instability. Administrators managing Linux systems utilizing CIFS should prioritize addressing this issue to prevent operational disruptions, especially in environments with slow-responding servers.

CVE
CVE-2026-97557
Severity
HIGH
CVSS
7.5
EPSS
0.66%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: smb: client: avoid leaking refcount in cifs_queue_oplock_break() cifs_queue_oplock_break() unconditionally takes a reference on the target file before queueing cifs_oplock_break(). Only that work item decreases the reference counter again. If another oplock break arrives while that work is still queued, queue_work() will return false and not queue this second work item. As a result, we will never reach the point to drop the file reference again and are leaking this reference. This can be triggered when interacting with a slow-responding server. As a result, later unmount operations for this file system will fail with BUG: Dentry ... still in use (1) [unmount of cifs cifs] VFS: Busy inodes after unmount of cifs (cifs) kernel BUG at fs/super.c:777! Fix this by only incrementing the reference count if the work has been queued successfully. Taking it after queue_work() is safe because all three callers hold tcon->open_file_lock across the call and _cifsFileInfo_put() decrements under that same lock, so a worker that starts the handler in the window cannot drop the reference before it has been taken.