← All Advisories

CVE-2026-72315

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-72315

Key Details

CVECVE-2026-72315
CVSS Score / Version7.8 (High) / CVSS v3.1
Updated2026-09-25
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is local; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

smb: client: fix busy dentry warning on unmount after DIO

Commit c68337442f03 ("cifs: Fix busy dentry used after unmounting") fixed

the issue in cifs where deferred close of a file led to a dentry reference

count not being released in umount, by flushing deferredclose_wq in

cifs_kill_sb() to solve it.

However, the cifs DIO path suffers from the same busy-dentry problem caused

by a delayed dentry reference-count release:

[dio] [cifsd] [close + umount]

netfs_unbuffered_write_iter_locked

...

cifs_demultiplex_thread

netfs_unbuffered_write

cifs_issue_write

netfs_wait_for_in_progress_stream [1]

...

netfs_write_subrequest_terminated

netfs_subreq_clear_in_progress

netfs_wake_collector // wake [1]

netfs_put_subrequest

netfs_put_request

queue_work(system_dfl_wq, xxx) [2]

// dio write return cifs_close

_cifsFileInfo_put

// cfile->count 2->1

--cfile->count [3]

// umount

cifs_kill_sb

kill_anon_super

// warning triggered!

shrink_dcache_for_umount [4]

[system_dfl_wq] [5]

netfs_free_request

...

_cifsFileInfo_put

// cfile->count 1->0

--cfile->count

queue_work(fileinfo_put_wq, xxx)

[fileinfo_put_wq] [6]

cifsFileInfo_put_work

cifsFileInfo_put_final

dput

If the umount path is triggered before [5], it results warning:

BUG: Dentry 00000000eab1f070{i=9a917b66ae404fec,n=test} still in use (1)

[unmount of cifs cifs]

The existing per-inode ictx->io_count wait in cifs_evict_inode() does not

help: it lives in the inode eviction path, which runs after

shrink_dcache_for_umount() has already warned about the busy dentries.

Fix it by adding a per-superblock outstanding-rreq counter that is

incremented in cifs_init_request() and decremented in cifs_free_request().

In cifs_kill_sb(), before kill_anon_super(), wait for this counter to reach

0 - which guarantees that all cleanup_work for this sb have run and thus

all relevant cfile puts are queued on fileinfo_put_wq or serverclose_wq.

Then drain the workqueue so the dentry refs are dropped.

This is a targeted wait, not a flush of the system-wide system_dfl_wq. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-72315
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-72315