Junglewise Threat Intelligence

CVE-2026-72356: Linux kernel CIFS missing credit release in cifs_issue_read()

CVE-2026-72356 · Severity: high · CVSS 7.5 · Published 2026-08-15

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's CIFS (SMB file system) implementation contains a resource management bug in the cifs_issue_read() function that fails to release protocol credits on read operation failures. When a read operation fails and is retried, the unreleased credits are overwritten, leading to credit leaks that can exhaust server resources and cause denial of service for legitimate CIFS operations.

Technical details

This is a resource leak vulnerability in fs/smb/client/file.c's cifs_issue_read() function. The CIFS protocol uses credits to manage concurrent operations; when a read subrequest fails, the code path fails to call add_credits_and_wake_if() to release the associated credits before terminating the subrequest. When the operation is retried, the credits value is overwritten, permanently leaking the credits. The vulnerability affects the netfslib read hooks implementation introduced in commit 69c3c023af25. No authentication or special privileges are required—any local or remote CIFS mount attempting read operations can trigger credit exhaustion. The fix is a one-line addition calling add_credits_and_wake_if() in the failure path.

Affected products

  • Linux Linux kernel Multiple kernel versions; vulnerable from 69c3c023af25 onwards

Timeline

  • 2026-08-15: disclosed
  • 2026-07-24: patched: Upstream fix c16b8c4cfb4fe2244cc33e469a93c1ab8684146b available from maintainers

References

Related threats