Missing Release of Resource after Effective Lifetime in Linux kernel - CVE-2026-97557
Published: September 28, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper reference count management in cifs_queue_oplock_break() when queueing oplock-break work. A remote attacker can trigger repeated oplock breaks while prior work remains queued to cause a denial of service.
The issue can be triggered when interacting with a slow-responding server.