Home

Description

In the Linux kernel, the following vulnerability has been resolved: smb: client: Avoid race in open_cached_dir with lease breaks A pre-existing valid cfid returned from find_or_create_cached_dir might race with a lease break, meaning open_cached_dir doesn't consider it valid, and thinks it's newly-constructed. This leaks a dentry reference if the allocation occurs before the queued lease break work runs. Avoid the race by extending holding the cfid_list_lock across find_or_create_cached_dir and when the result is checked.

PUBLISHED Reserved 2025-04-16 | Published 2025-05-20 | Updated 2026-05-23 | Assigner Linux

Product status

Default status
unaffected

81ba10959970d15c388bf29866b01b62f387e6a3 (git) before 2ed98e89ebc2e1bc73534dc3c18cb7843a889ff9
affected

81ba10959970d15c388bf29866b01b62f387e6a3 (git) before 571dcf3d27b24800c171aea7b5e04ff06d10e2e9
affected

81ba10959970d15c388bf29866b01b62f387e6a3 (git) before 2407265dc32bc8cc45b62a612c2a214ba9038e8b
affected

81ba10959970d15c388bf29866b01b62f387e6a3 (git) before 3ca02e63edccb78ef3659bebc68579c7224a6ca2
affected

436be190fbf81e5d84040dabf9cb7be06a94dc5d (git)
affected

6.5.10 (semver) before 6.6
affected

Default status
affected

6.6
affected

Any version before 6.6
unaffected

6.6.91 (semver)
unaffected

6.12.29 (semver)
unaffected

6.14.7 (semver)
unaffected

6.15 (original_commit_for_fix)
unaffected

References

git.kernel.org/...c/2ed98e89ebc2e1bc73534dc3c18cb7843a889ff9

git.kernel.org/...c/571dcf3d27b24800c171aea7b5e04ff06d10e2e9

git.kernel.org/...c/2407265dc32bc8cc45b62a612c2a214ba9038e8b

git.kernel.org/...c/3ca02e63edccb78ef3659bebc68579c7224a6ca2

cve.org (CVE-2025-37954)

nvd.nist.gov (CVE-2025-37954)

Download JSON