CVE-2026-64108 Details
Description
In the Linux kernel, the following vulnerability has been resolved: cifs: Fix busy dentry used after unmounting Since commit 340cea84f691c ("cifs: open files should not hold ref on superblock"), cifs file only holds the dentry ref_cnt, the cifs file close work(cfile->deferred) could be executed after unmounting, which will trigger a warning in generic_shutdown_super: BUG: Dentry 00000000a14a6845{i=c,n=file} still in use (1) [unmount of cifs cifs] The detailed processs is: process A process B kworker fd = open(PATH) vfs_open file->__f_path = *path // dentry->d_lockref.count = 1 cifs_open cifs_new_fileinfo cfile->dentry = dget(dentry) // dentry->d_lockref.count = 2 close(fd) __fput cifs_close queue_delayed_work(deferredclose_wq, cfile->deferred) dput(dentry) // dentry->d_lockref.count = 1 smb2_deferred_work_close _cifsFileInfo_put list_del(&cifs_file->flist) umount cleanup_mnt deactivate_super cifs_kill_sb cifs_close_all_deferred_files_sb cifs_close_all_deferred_files // cannot find cfile, skip _cifsFileInfo_put kill_anon_super generic_shutdown_super shrink_dcache_for_umount umount_check WARN ! // dentry->d_lockref.count = 1 cifsFileInfo_put_final dput(cifs_file->dentry) // dentry->d_lockref.count = 0 Fix it by flushing 'deferredclose_wq' before calling kill_anon_super. Fetch a reproducer in https://bugzilla.kernel.org/show_bug.cgi?id=221548.
A use-after-unmount vulnerability has been identified in the CIFS (Common Internet File System) implementation of the Linux kernel. This issue arises because, since a previous commit, CIFS files only maintain a reference count for the dentry (directory entry) but not for the superblock. As a result, the deferred close operation for CIFS files can be executed after the filesystem has been unmounted, leading to a warning during the unmount process. The warning indicates that a dentry is still in use, which can cause issues with filesystem integrity.
The vulnerability has been fixed in the Linux kernel. Users should upgrade to the latest version of the stable Linux kernel where this issue has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/5e7d9d0805e58fa3760894e73115b7a74024fd07 | kernel.org | Patch |
| https://git.kernel.org/stable/c/bdc349a87f1fb02c18c4071858a06542bfea783d | kernel.org | Patch |
| https://git.kernel.org/stable/c/c68337442f03953237a94577beb468ab2662a851 | kernel.org | Patch |
| https://git.kernel.org/stable/c/c7364cea52531534676b9f7dbc0a477c11f4c050 | kernel.org | Patch |
| https://git.kernel.org/stable/c/e1ffa6cf662383f95816eed1b623429d82675e75 | kernel.org | Patch |
| https://git.kernel.org/stable/c/f2deaa2f409a4598eaa10f2a93a676c0632af248 | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 6.1.167, < 6.1.175 >= 6.6.130, < 6.6.142 >= 6.12.78, < 6.12.92 >= 6.18.20, < 6.18.34 >= 6.19.10, < 7.0 >= 7.0.1, < 7.0.11 7.0 - 7.0 rc3 7.0 rc4 7.0 rc5 7.0 rc6 7.0 rc7 7.1 rc1 7.1 rc2 7.1 rc3 7.1 rc4 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 12, 2026 | Initial Analysis | [email protected] |
| Jul 20, 2026 | CVE Modified | kernel.org |
| Jul 19, 2026 | New CVE Received | kernel.org |