OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-97562

HIGH · CVSS 7.5 EPSS 0.41%

Source: NVD + CISA KEV + EPSS · Published 2026-09-25 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

A vulnerability in the Linux kernel affects the SMB client, where a race condition can lead to a use-after-free scenario due to improper handling of superblock pointers during DFS automount expiry. This flaw can potentially allow attackers to exploit the vulnerability, leading to system instability or unauthorized access. Organizations using Linux systems that implement SMB should prioritize applying patches to mitigate this risk.

CVE
CVE-2026-97562
Severity
HIGH
CVSS
7.5
EPSS
0.41%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: smb: client: pin DFS superblock in iterator callback tcon_super_cb() stores a raw superblock pointer, but __cifs_get_super() takes its active reference only after iterate_supers_type() has dropped s_umount and its passive reference. Concurrent DFS automount expiry can therefore free the superblock before cifs_sb_active() uses it. A deterministic KASAN test reproduces the race as: BUG: KASAN: slab-use-after-free in cifs_sb_active+0x77/0x80 The same test passes with this change applied. Take the active reference in the callback while iterate_supers_type() still holds s_umount shared. cifs_put_tcp_super() remains the matching release.