7.8
CVE-2026-72315
- EPSS 0.17%
- Veröffentlicht 15.08.2026 05:55:29
- Zuletzt bearbeitet 03.10.2026 11:17:37
- Erkennungen
smb: client: fix busy dentry warning on unmount after DIO
In the Linux kernel, the following vulnerability has been resolved:
smb: client: fix busy dentry warning on unmount after DIO
Commit c68337442f03 ("cifs: Fix busy dentry used after unmounting") fixed
the issue in cifs where deferred close of a file led to a dentry reference
count not being released in umount, by flushing deferredclose_wq in
cifs_kill_sb() to solve it.
However, the cifs DIO path suffers from the same busy-dentry problem caused
by a delayed dentry reference-count release:
[dio] [cifsd] [close + umount]
netfs_unbuffered_write_iter_locked
...
cifs_demultiplex_thread
netfs_unbuffered_write
cifs_issue_write
netfs_wait_for_in_progress_stream [1]
...
netfs_write_subrequest_terminated
netfs_subreq_clear_in_progress
netfs_wake_collector // wake [1]
netfs_put_subrequest
netfs_put_request
queue_work(system_dfl_wq, xxx) [2]
// dio write return cifs_close
_cifsFileInfo_put
// cfile->count 2->1
--cfile->count [3]
// umount
cifs_kill_sb
kill_anon_super
// warning triggered!
shrink_dcache_for_umount [4]
[system_dfl_wq] [5]
netfs_free_request
...
_cifsFileInfo_put
// cfile->count 1->0
--cfile->count
queue_work(fileinfo_put_wq, xxx)
[fileinfo_put_wq] [6]
cifsFileInfo_put_work
cifsFileInfo_put_final
dput
If the umount path is triggered before [5], it results warning:
BUG: Dentry 00000000eab1f070{i=9a917b66ae404fec,n=test} still in use (1)
[unmount of cifs cifs]
The existing per-inode ictx->io_count wait in cifs_evict_inode() does not
help: it lives in the inode eviction path, which runs after
shrink_dcache_for_umount() has already warned about the busy dentries.
Fix it by adding a per-superblock outstanding-rreq counter that is
incremented in cifs_init_request() and decremented in cifs_free_request().
In cifs_kill_sb(), before kill_anon_super(), wait for this counter to reach
0 - which guarantees that all cleanup_work for this sb have run and thus
all relevant cfile puts are queued on fileinfo_put_wq or serverclose_wq.
Then drain the workqueue so the dentry refs are dropped.
This is a targeted wait, not a flush of the system-wide system_dfl_wq.Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
0e4b8faaaebe3137bec5723ef2b3cb0437fb38fd
Version <
f7748b551010c021d92f0125e37f32ac0c376d8a
Status
affected
Version
f655467a9973f964b267871e5fef533ad5014494
Version <
9fc87899276af941ecf3045798887db7deb85605
Status
affected
Version
340cea84f691c5206561bb2e0147158fe02070be
Version <
f0eac9c3c3711f24efc2aaf12b8ec3e54a38c214
Status
affected
Version
340cea84f691c5206561bb2e0147158fe02070be
Version <
75f5c412fa867efa0bf9b646bffe0d912109e84a
Status
affected
Version
708c276f516d27beaded7f372ac8111cee43926c
Status
affected
Version
0629a1a187e424373364d681b42b101894bdb548
Status
affected
Version
30afc6ea72cc6cf7c8d579e79b64232801c38d08
Status
affected
Version
6.12.78
Version <
6.12.112
Status
affected
Version
6.18.20
Version <
6.18.54
Status
affected
Version
6.1.167
Version <
6.2
Status
affected
Version
6.6.130
Version <
6.7
Status
affected
Version
6.19.10
Version <
6.20
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
7.0
Status
affected
Version
0
Version <
7.0
Status
unaffected
Version <=
6.12.*
Version
6.12.112
Status
unaffected
Version <=
6.18.*
Version
6.18.54
Status
unaffected
Version <=
7.1.*
Version
7.1.5
Status
unaffected
Version <=
*
Version
7.2
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.17% | 0.062 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
https://git.kernel.org/stable/c/f0eac9c3c3711f24efc2aaf12b8ec3e54a38c214
https://git.kernel.org/stable/c/75f5c412fa867efa0bf9b646bffe0d912109e84a
https://git.kernel.org/stable/c/9fc87899276af941ecf3045798887db7deb85605
https://git.kernel.org/stable/c/f7748b551010c021d92f0125e37f32ac0c376d8a