CVE-2026-97562
CVE CVE-2026-97562EUVD EUVD-2026-86870Published 2026-09-25T10:21:50.000ZLast changed 2026-09-25T14:41:15.000ZCVSS 7.5
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: smb: client: pin DFS superblock in iterator callback tcon_super_cb() stores a raw superblock pointer, but __cifs_get_super() takes its active reference only after iterate_supers_type() has dropped s_umount and its passive reference. Concurrent DFS automount expiry can therefore free the superblock before cifs_sb_active() uses it. A deterministic KASAN test reproduces the race as: BUG: KASAN: slab-use-after-free in cifs_sb_active+0x77/0x80 The same test passes with this change applied. Take the active reference in the callback while iterate_supers_type() still holds s_umount shared. cifs_put_tcp_super() remains the matching release.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux bacd704a95ad0b93af995aae4a523aa046f46563 <5b01a8c0209690db75341528ec53fd87e0ac1460; patch: 7.3-rc3; patch: 6.12.111; bacd704a95ad0b93af995aae4a523aa046f46563 <ea43a15cea36dc5ddd832be5bddeac7dd804cbcf; patch: 7.2.7; patch: 6.18.53; 5.7; bacd704a95ad0b93af995aae4a523aa046f46563 <d806d5a85dcbe2a0f181b2f0f9f61ddfbefa1818; patch: 0; bacd704a95ad0b93af995aae4a523aa046f46563 <a6b6561522212af852c9ad8a7dca8d59ef2c7377
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.