{"id":"CVE-2026-97556","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: avoid leaking refcount when cifs_sb_tlink() fails\n\ncifs_oplock_break() takes over the reference that\ncifs_queue_oplock_break() acquired when it queued the …","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: avoid leaking refcount when cifs_sb_tlink() fails\n\ncifs_oplock_break() takes over the reference that\ncifs_queue_oplock_break() acquired when it queued the …","severity":"none","vendor":"Linux","product":"Linux","affected":["Linux >= e8f5f849ffce24490eb9449e98312b66c0dba76f < 9ec991e148368e3207e98134c509a625097f7693","Linux >= e8f5f849ffce24490eb9449e98312b66c0dba76f < dd03fd658ea59821505e0e643b6b7cbdf51c4e1d","Linux >= e8f5f849ffce24490eb9449e98312b66c0dba76f < 1d1b0f1d812a4011a57bc6c70492c34a2e46c6dd","Linux >= e8f5f849ffce24490eb9449e98312b66c0dba76f < 23b26f4408ac3f35a482d2e5cf6fc865d4201b71","Linux b99f490ea87ebcca3a429fd8837067feb56a4c7c","Linux 5ee28bcfbaacf289eb25c662a2862542ea6ce6a7","Linux 6b67a6d2e50634fe127e656147c81915955e9f5e","Linux >= 5.15.128 < 5.16","Linux >= 6.1.47 < 6.2","Linux >= 6.4.12 < 6.5","Linux 6.5"],"published":"2026-09-25","updated":"2026-09-25","sourceUpdated":"2026-09-25T11:17:06.077","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-97556","references":[{"url":"https://git.kernel.org/stable/c/1d1b0f1d812a4011a57bc6c70492c34a2e46c6dd","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/23b26f4408ac3f35a482d2e5cf6fc865d4201b71","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9ec991e148368e3207e98134c509a625097f7693","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/dd03fd658ea59821505e0e643b6b7cbdf51c4e1d","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-25T11:06:38.916Z","slug":"CVE-2026-97556","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: avoid leaking refcount when cifs_sb_tlink() fails\n\ncifs_oplock_break() takes over the reference that\ncifs_queue_oplock_break() acquired when it queued the work, and drops it\nwith _cifsFileInfo_put() once the break has been processed.\n\nOnly in setups with \"-o multiuser\", cifs_sb_tlink() may fail, at which\npoint cifs_oplock_break() returns without putting the file reference,\nmirroring the reference leak we already fixed in the companion patch to\ncifs_queue_oplock_break().\n\nThis would trigger a crash due to busy inodes on the next unmount:\n\n  BUG: Dentry ... still in use (1) [unmount of cifs cifs]\n  VFS: Busy inodes after unmount of cifs (cifs)\n\nDrop the reference on that path as well. Doing so before the out label\nmirrors the normal path, which also puts the reference before\ncifs_done_oplock_break().\n\nFound by Sashiko code review. The failure path was not exercised at\nruntime.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}