← All Advisories

CVE-2026-97558

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-97558

Key Details

CVECVE-2026-97558
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

smb: client: fix cifsFileInfo reference leak in deferred close

When cifs_close() defers a close, it hands the cifsFileInfo reference

of the closing struct file to the queued work. Each execution of

smb2_deferred_work_close() drops one such reference.

deferred_close_scheduled can be false while the work is pending: the

workqueue clears PENDING when the callback starts to run, before the

callback clears the flag under deferred_lock. A close in that

interval requeues the running work, and the callback then clears the

flag, leaving the requeued work pending with the flag down. A later

cifs_open() can reuse the handle and its cifs_close() reaches the

same branch: queue_delayed_work() fails because the work is still

pending, but cifs_close() returns without dropping the closing file's

reference. The cifsFileInfo count stays pinned and its tlink, dentry

and server handle are leaked.

Check the return value and hand off the reference only when work was

actually queued. Otherwise, use the shared _cifsFileInfo_put(), like

the mod_delayed_work() branch above: the pending execution already

owns its reference.

This issue was found by an in-house static analysis tool. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-97558
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-97558