๐Ÿ” CVE Alert

CVE-2026-97562

UNKNOWN 0.0

smb: client: pin DFS superblock in iterator callback

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: smb: client: pin DFS superblock in iterator callback tcon_super_cb() stores a raw superblock pointer, but __cifs_get_super() takes its active reference only after iterate_supers_type() has dropped s_umount and its passive reference. Concurrent DFS automount expiry can therefore free the superblock before cifs_sb_active() uses it. A deterministic KASAN test reproduces the race as: BUG: KASAN: slab-use-after-free in cifs_sb_active+0x77/0x80 The same test passes with this change applied. Take the active reference in the callback while iterate_supers_type() still holds s_umount shared. cifs_put_tcp_super() remains the matching release.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 25, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
bacd704a95ad0b93af995aae4a523aa046f46563 < ea43a15cea36dc5ddd832be5bddeac7dd804cbcf bacd704a95ad0b93af995aae4a523aa046f46563 < a6b6561522212af852c9ad8a7dca8d59ef2c7377 bacd704a95ad0b93af995aae4a523aa046f46563 < 5b01a8c0209690db75341528ec53fd87e0ac1460 bacd704a95ad0b93af995aae4a523aa046f46563 < d806d5a85dcbe2a0f181b2f0f9f61ddfbefa1818
Linux / Linux
5.7

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/ea43a15cea36dc5ddd832be5bddeac7dd804cbcf git.kernel.org: https://git.kernel.org/stable/c/a6b6561522212af852c9ad8a7dca8d59ef2c7377 git.kernel.org: https://git.kernel.org/stable/c/5b01a8c0209690db75341528ec53fd87e0ac1460 git.kernel.org: https://git.kernel.org/stable/c/d806d5a85dcbe2a0f181b2f0f9f61ddfbefa1818