{"id":"CVE-2026-72315","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: fix busy dentry warning on unmount after DIO\n\nCommit c68337442f03 (\"cifs: Fix busy dentry used after unmounting\") fixed\nthe issue in cifs where deferred cl…","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: fix busy dentry warning on unmount after DIO\n\nCommit c68337442f03 (\"cifs: Fix busy dentry used after unmounting\") fixed\nthe issue in cifs where deferred cl…","severity":"high","cvss":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","vendor":"Linux","product":"Linux","affected":["Linux >= f655467a9973f964b267871e5fef533ad5014494 < 9fc87899276af941ecf3045798887db7deb85605","Linux >= 340cea84f691c5206561bb2e0147158fe02070be < f0eac9c3c3711f24efc2aaf12b8ec3e54a38c214","Linux >= 340cea84f691c5206561bb2e0147158fe02070be < 75f5c412fa867efa0bf9b646bffe0d912109e84a","Linux 708c276f516d27beaded7f372ac8111cee43926c","Linux 0629a1a187e424373364d681b42b101894bdb548","Linux 0e4b8faaaebe3137bec5723ef2b3cb0437fb38fd","Linux 30afc6ea72cc6cf7c8d579e79b64232801c38d08","Linux >= 6.18.20 < 6.18.54","Linux >= 6.1.167 < 6.2","Linux >= 6.6.130 < 6.7","Linux >= 6.12.78 < 6.13","Linux >= 6.19.10 < 6.20","Linux 7.0"],"published":"2026-08-15","updated":"2026-09-25","sourceUpdated":"2026-09-25T15:17:54.913","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-72315","references":[{"url":"https://git.kernel.org/stable/c/75f5c412fa867efa0bf9b646bffe0d912109e84a","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9fc87899276af941ecf3045798887db7deb85605","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f0eac9c3c3711f24efc2aaf12b8ec3e54a38c214","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd","cve.org"],"epss":0.00165,"epssPercentile":0.05079,"ingestedAt":"2026-09-25T15:10:56.362Z","slug":"CVE-2026-72315","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: fix busy dentry warning on unmount after DIO\n\nCommit c68337442f03 (\"cifs: Fix busy dentry used after unmounting\") fixed\nthe issue in cifs where deferred close of a file led to a dentry reference\ncount not being released in umount, by flushing deferredclose_wq in\ncifs_kill_sb() to solve it.\n\nHowever, the cifs DIO path suffers from the same busy-dentry problem caused\nby a delayed dentry reference-count release:\n\n\t[dio]\t\t\t[cifsd]\t\t\t[close + umount]\nnetfs_unbuffered_write_iter_locked\n...\n\t\t\t\tcifs_demultiplex_thread\n netfs_unbuffered_write\n  cifs_issue_write\n  netfs_wait_for_in_progress_stream [1]\n\t\t\t\t...\n\t\t\t\t netfs_write_subrequest_terminated\n\t\t\t\t  netfs_subreq_clear_in_progress\n\t\t\t\t   netfs_wake_collector // wake [1]\n\t\t\t\t  netfs_put_subrequest\n netfs_put_request\n  queue_work(system_dfl_wq, xxx) [2]\n // dio write return\t\t\t\t\tcifs_close\n\t\t\t\t\t\t\t _cifsFileInfo_put\n\t\t\t\t\t\t\t  // cfile->count 2->1\n\t\t\t\t\t\t\t  --cfile->count [3]\n\n\t\t\t\t\t\t\t// umount\n\t\t\t\t\t\t\tcifs_kill_sb\n\t\t\t\t\t\t\t kill_anon_super\n\t\t\t\t\t\t\t  // warning triggered!\n\t\t\t\t\t\t\t  shrink_dcache_for_umount [4]\n[system_dfl_wq] [5]\nnetfs_free_request\n ...\n _cifsFileInfo_put\n  // cfile->count 1->0\n  --cfile->count\n  queue_work(fileinfo_put_wq, xxx)\n\n[fileinfo_put_wq] [6]\ncifsFileInfo_put_work\n cifsFileInfo_put_final\n  dput\n\nIf the umount path is triggered before [5], it results warning:\nBUG: Dentry 00000000eab1f070{i=9a917b66ae404fec,n=test}  still in use (1)\n[unmount of cifs cifs]\n\nThe existing per-inode ictx->io_count wait in cifs_evict_inode() does not\nhelp: it lives in the inode eviction path, which runs after\nshrink_dcache_for_umount() has already warned about the busy dentries.\n\nFix it by adding a per-superblock outstanding-rreq counter that is\nincremented in cifs_init_request() and decremented in cifs_free_request().\nIn cifs_kill_sb(), before kill_anon_super(), wait for this counter to reach\n0 - which guarantees that all cleanup_work for this sb have run and thus\nall relevant cfile puts are queued on fileinfo_put_wq or serverclose_wq.\nThen drain the workqueue so the dentry refs are dropped.\n\nThis is a targeted wait, not a flush of the system-wide system_dfl_wq.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":43,"depthScoreParts":{"impact":42.9,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}