CVE-2026-72315
Received Received - Intake

Dentry Reference Leak in Linux Kernel SMB Client

Vulnerability report for CVE-2026-72315, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-15

Last updated on: 2026-08-17

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix busy dentry warning on unmount after DIO Commit c68337442f03 ("cifs: Fix busy dentry used after unmounting") fixed the issue in cifs where deferred close of a file led to a dentry reference count not being released in umount, by flushing deferredclose_wq in cifs_kill_sb() to solve it. However, the cifs DIO path suffers from the same busy-dentry problem caused by a delayed dentry reference-count release: [dio] [cifsd] [close + umount] netfs_unbuffered_write_iter_locked ... cifs_demultiplex_thread netfs_unbuffered_write cifs_issue_write netfs_wait_for_in_progress_stream [1] ... netfs_write_subrequest_terminated netfs_subreq_clear_in_progress netfs_wake_collector // wake [1] netfs_put_subrequest netfs_put_request queue_work(system_dfl_wq, xxx) [2] // dio write return cifs_close _cifsFileInfo_put // cfile->count 2->1 --cfile->count [3] // umount cifs_kill_sb kill_anon_super // warning triggered! shrink_dcache_for_umount [4] [system_dfl_wq] [5] netfs_free_request ... _cifsFileInfo_put // cfile->count 1->0 --cfile->count queue_work(fileinfo_put_wq, xxx) [fileinfo_put_wq] [6] cifsFileInfo_put_work cifsFileInfo_put_final dput If the umount path is triggered before [5], it results warning: BUG: Dentry 00000000eab1f070{i=9a917b66ae404fec,n=test} still in use (1) [unmount of cifs cifs] The existing per-inode ictx->io_count wait in cifs_evict_inode() does not help: it lives in the inode eviction path, which runs after shrink_dcache_for_umount() has already warned about the busy dentries. Fix it by adding a per-superblock outstanding-rreq counter that is incremented in cifs_init_request() and decremented in cifs_free_request(). In cifs_kill_sb(), before kill_anon_super(), wait for this counter to reach 0 - which guarantees that all cleanup_work for this sb have run and thus all relevant cfile puts are queued on fileinfo_put_wq or serverclose_wq. Then drain the workqueue so the dentry refs are dropped. This is a targeted wait, not a flush of the system-wide system_dfl_wq.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-15
Last Modified
2026-08-17
Generated
2026-09-04
AI Q&A
2026-08-15
EPSS Evaluated
2026-09-03
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel involves a busy dentry warning during unmount operations after Direct I/O (DIO) writes. The issue occurs because dentry reference counts are not properly released when a CIFS (Common Internet File System) client unmounts a filesystem after performing DIO writes. The kernel's cleanup process triggers a warning because the dentry remains in use even after the unmount process begins.

Detection Guidance

This vulnerability may trigger a kernel warning during unmount of a CIFS share when a busy dentry is detected. Monitor kernel logs for messages like 'BUG: Dentry still in use' during CIFS unmount operations. Check for warnings in dmesg or /var/log/kern.log after unmounting CIFS shares.

Impact Analysis

This vulnerability can cause system instability during unmount operations, particularly when using CIFS with Direct I/O. It may lead to kernel warnings or errors, potentially disrupting file operations or causing delays in unmounting filesystems. Systems relying on CIFS for network storage could experience unexpected behavior during shutdown or filesystem unmounting.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR, HIPAA, or similar standards as it pertains to a Linux kernel issue involving dentry reference counts during unmount operations in the CIFS client. Compliance impacts would only occur if this bug led to data corruption, unauthorized access, or service disruptions in systems handling sensitive data.

Mitigation Strategies

Apply the Linux kernel patch that resolves this issue. Ensure your kernel version includes the fix for the busy dentry warning on CIFS unmount. If immediate patching is not possible, avoid unmounting CIFS shares while write operations are in progress to reduce risk.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-72315. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart