Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-96039.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-96039
Upstream
Published
2026-08-15T06:22:04Z
Modified
2026-08-29T05:27:27Z
Summary
CVE-2026-72315 affecting package kernel 6.6.150.1-1
Details

In the Linux kernel, the following vulnerability has been resolved:

smb: client: fix busy dentry warning on unmount after DIO

Commit c68337442f03 ("cifs: Fix busy dentry used after unmounting") fixed the issue in cifs where deferred close of a file led to a dentry reference count not being released in umount, by flushing deferredclosewq in cifskill_sb() to solve it.

However, the cifs DIO path suffers from the same busy-dentry problem caused by a delayed dentry reference-count release:

[dio]           [cifsd]         [close + umount]

netfsunbufferedwriteiterlocked ... cifsdemultiplexthread netfsunbufferedwrite cifsissuewrite netfswaitforinprogressstream [1] ... netfswritesubrequestterminated netfssubreqclearinprogress netfswakecollector // wake [1] netfsputsubrequest netfsputrequest queuework(systemdflwq, xxx) [2] // dio write return cifsclose cifsFileInfoput // cfile->count 2->1 --cfile->count [3]

                        // umount
                        cifs_kill_sb
                         kill_anon_super
                          // warning triggered!
                          shrink_dcache_for_umount [4]

[systemdflwq] [5] netfsfreerequest ... cifsFileInfoput // cfile->count 1->0 --cfile->count queuework(fileinfoput_wq, xxx)

[fileinfoputwq] [6] cifsFileInfoputwork cifsFileInfoputfinal dput

If the umount path is triggered before [5], it results warning: BUG: Dentry 00000000eab1f070{i=9a917b66ae404fec,n=test} still in use (1) [unmount of cifs cifs]

The existing per-inode ictx->iocount wait in cifsevictinode() does not help: it lives in the inode eviction path, which runs after shrinkdcacheforumount() has already warned about the busy dentries.

Fix it by adding a per-superblock outstanding-rreq counter that is incremented in cifsinitrequest() and decremented in cifsfreerequest(). In cifskillsb(), before killanonsuper(), wait for this counter to reach 0 - which guarantees that all cleanupwork for this sb have run and thus all relevant cfile puts are queued on fileinfoputwq or serverclosewq. Then drain the workqueue so the dentry refs are dropped.

This is a targeted wait, not a flush of the system-wide systemdflwq.

References

Affected packages

Azure Linux:3 / kernel

Package

Name
kernel
Purl
pkg:rpm/azure-linux/kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
6.6.150.1-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-96039.json"