{"id":"CVE-2026-97556","published":"2026-09-25T11:17:06.077","lastModified":"2026-09-25T11:17:06.077","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: avoid leaking refcount when cifs_sb_tlink() fails\n\ncifs_oplock_break() takes over the reference that\ncifs_queue_oplock_break() acquired when it queued the work, and drops it\nwith _cifsFileInfo_put() once the break has been processed.\n\nOnly in setups with \"-o multiuser\", cifs_sb_tlink() may fail, at which\npoint cifs_oplock_break() returns without putting the file reference,\nmirroring the reference leak we already fixed in the companion patch to\ncifs_queue_oplock_break().\n\nThis would trigger a crash due to busy inodes on the next unmount:\n\n  BUG: Dentry ... still in use (1) [unmount of cifs cifs]\n  VFS: Busy inodes after unmount of cifs (cifs)\n\nDrop the reference on that path as well. Doing so before the out label\nmirrors the normal path, which also puts the reference before\ncifs_done_oplock_break().\n\nFound by Sashiko code review. The failure path was not exercised at\nruntime.","cvssScore":null,"cvssSeverity":null,"cvssVector":null,"cwes":[],"vendors":[],"products":[],"references":[{"url":"https://git.kernel.org/stable/c/1d1b0f1d812a4011a57bc6c70492c34a2e46c6dd","tags":[]},{"url":"https://git.kernel.org/stable/c/23b26f4408ac3f35a482d2e5cf6fc865d4201b71","tags":[]},{"url":"https://git.kernel.org/stable/c/9ec991e148368e3207e98134c509a625097f7693","tags":[]},{"url":"https://git.kernel.org/stable/c/dd03fd658ea59821505e0e643b6b7cbdf51c4e1d","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}