Memory leak in Linux kernel - CVE-2026-97556
Published: September 28, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a missing reference count release in cifs_oplock_break() in the SMB client when handling an oplock break after cifs_sb_tlink() fails. A local user can trigger an oplock break that encounters a cifs_sb_tlink() failure to cause a denial of service.
Only SMB mounts using the multiuser option are affected.