CyberRota Analysis
AI-GeneratedA vulnerability in the Linux kernel affects the SMB client, where a race condition can lead to a use-after-free scenario due to improper handling of superblock pointers during DFS automount expiry. This flaw can potentially allow attackers to exploit the vulnerability, leading to system instability or unauthorized access. Organizations using Linux systems that implement SMB should prioritize applying patches to mitigate this risk.
Original NVD Description
In the Linux kernel, the following vulnerability has been resolved: smb: client: pin DFS superblock in iterator callback tcon_super_cb() stores a raw superblock pointer, but __cifs_get_super() takes its active reference only after iterate_supers_type() has dropped s_umount and its passive reference. Concurrent DFS automount expiry can therefore free the superblock before cifs_sb_active() uses it. A deterministic KASAN test reproduces the race as: BUG: KASAN: slab-use-after-free in cifs_sb_active+0x77/0x80 The same test passes with this change applied. Take the active reference in the callback while iterate_supers_type() still holds s_umount shared. cifs_put_tcp_super() remains the matching release.