JVNDB-2026-028072 | |
LinuxのLinux Kernelにおける不特定の脆弱性 | |
| 概要 | |
Linuxカーネルにおいて、以下の脆弱性が修正されました:cifs: アンマウント後に使用されるビジーダントリの参照カウントに関する修正。コミット340cea84f691c("cifs: open files should not hold ref on superblock")以降、cifsファイルはdentryのref_cntのみを保持しています。cifsファイルのクローズ処理(cfile->deferred)はアンマウント後に実行される可能性があり、これによりgeneric_shutdown_superで以下の警告が発生していました:BUG: Dentry 00000000a14a6845{i=c,n=file} still in use (1) [unmount of cifs cifs]詳細なプロセスは以下の通りです: プロセスA プロセスB kworker fd = open(PATH) vfs_open file->__f_path = *path // dentry->d_lockref.count = 1 cifs_open cifs_new_fileinfo cfile->dentry = dget(dentry) // dentry->d_lockref.count = 2 close(fd) __fput cifs_close queue_delayed_work(deferredclose_wq, cfile->deferred) dput(dentry) // dentry->d_lockref.count = 1 smb2_deferred_work_close _cifsFileInfo_put list_del(&cifs_file->flist) umount cleanup_mnt deactivate_super cifs_kill_sb cifs_close_all_deferred_files_sb cifs_close_all_deferred_files // cfileが見つからず、_cifsFileInfo_putの呼び出しがスキップされる kill_anon_super generic_shutdown_super shrink_dcache_for_umount umount_check WARN ! // dentry->d_lockref.count = 1 cifsFileInfo_put_final dput(cifs_file->dentry) // dentry->d_lockref.count = 0修正方法は、kill_anon_superを呼び出す前に'deferredclose_wq'をフラッシュすることです。再現コードはhttps://bugzilla.kernel.org/show_bug.cgi?id=221548 から入手可能です。 | |
| CVSS による深刻度 (CVSS とは?) | |
|
CVSS v3 による深刻度
基本値: 7.8 (重要) [その他]
| |
| 影響を受けるシステム | |
|
| |
Linux | |
|
| |
| 想定される影響 | |
・当該ソフトウェアが扱う全ての情報が外部に漏れる可能性があります。 | |
| 対策 | |
リリース情報、またはパッチ情報が公開されています。参考情報を参照して適切な対策を実施してください。 | |
| ベンダ情報 | |
|
| |
| CWEによる脆弱性タイプ一覧 CWEとは? | |
| |
| 共通脆弱性識別子(CVE) CVEとは? | |
|
| |
| 参考情報 | |
| |
| 更新履歴 | |
|
| 公表日 | 2026/07/19 |
| 登録日 | 2026/08/13 |
| 最終更新日 | 2026/08/13 |



