понедельник

[Bug 2155632] AudioDevicesInUse.txt

apport information ** Attachment added: "AudioDevicesInUse.txt" https://bugs.launchpad.net/bugs/2155632/+attachment/6003344/+files/AudioDevicesInUse.txt -- You received this bug notification because you are subscribed to linux in Ubuntu. Matching subscriptions: Bgg, Bmail, Nb https://bugs.launchpad.net/bugs/2155632 Title: Mute LED not working on HP Pavilion 15-cs3xxx (ALC295, subsystem 0x103c86e3) Status in linux package in Ubuntu: New Bug description: The mute button LED works correctly on Windows but does not respond on Linux. Hardware: - Model: HP Pavilion Laptop 15-cs3xxx - Subsystem ID: 0x103c86e3 - Codec: Realtek ALC295 - Kernel: 7.0.0-22-generic (Kubuntu 26.04) The hda::mute LED is visible in /sys/class/leds/ but writing to brightness has no effect. No COEF registers respond to hda-verb commands. The subsystem ID 0x103c86e3 is not present in patch_realtek.c. A quirk similar to ALC295_FIXUP_HP_MUTE_LED_COEFBIT11 may be needed for this subsystem ID.D ProblemType: Bug DistroRelease: Ubuntu 26.04 Package: linux-image-7.0.0-22-generic 7.0.0-22.22 ProcVersionSignature: Ubuntu 7.0.0-22.22-generic 7.0.0 Uname: Linux 7.0.0-22-generic x86_64 NonfreeKernelModules: nvidia_modeset nvidia ApportVersion: 2.34.0-0ubuntu2 Architecture: amd64 AudioDevicesInUse: USER PID ACCESS COMMAND /dev/snd/controlC1: antonio 1819 F.... wireplumber /dev/snd/controlC0: antonio 1819 F.... wireplumber /dev/snd/seq: antonio 1817 F.... pipewire CasperMD5CheckResult: unknown CurrentDesktop: KDE Date: Fri Jun 5 12:06:24 2026 InstallationDate: Installed on 2026-05-19 (17 days ago) InstallationMedia: Kubuntu 26.04 "Resolute Raccoon" - Release amd64 (20260423) Lsusb: Bus 001 Device 001: ID 1d6b:0002 Linux Foundation 2.0 root hub Bus 001 Device 002: ID 04f2:b634 Chicony Electronics Co., Ltd HP Wide Vision FHD Camera Bus 001 Device 003: ID 8087:0aaa Intel Corp. Bluetooth 9460/9560 Jefferson Peak (JfP) Bus 002 Device 001: ID 1d6b:0003 Linux Foundation 3.0 root hub MachineType: HP HP Pavilion Laptop 15-cs3xxx ProcFB: 0 i915drmfb 1 nvidia-drmdrmfb ProcKernelCmdLine: BOOT_IMAGE=/boot/vmlinuz-7.0.0-22-generic root=UUID=f6336a40-bf4f-43f2-ab94-33cf9429e187 ro quiet splash pcie_aspm=off nvidia-drm.modeset=1 PulseList: Error: command ['pacmd', 'list'] failed with exit code 1: No PulseAudio daemon running, or not running as session daemon. SourcePackage: linux UpgradeStatus: No upgrade log present (probably fresh install) dmi.bios.date: 08/23/2024 dmi.bios.release: 15.23 dmi.bios.vendor: Insyde dmi.bios.version: F.23 dmi.board.asset.tag: Type2 - Board Asset Tag dmi.board.name: 86E3 dmi.board.vendor: HP dmi.board.version: 95.36 dmi.chassis.asset.tag: Chassis Asset Tag dmi.chassis.type: 10 dmi.chassis.vendor: HP dmi.chassis.version: Chassis Version dmi.ec.firmware.release: 95.36 dmi.modalias: dmi:bvnInsyde:bvrF.23:bd08/23/2024:br15.23:efr95.36:svnHP:pnHPPavilionLaptop15-cs3xxx:pvrType1ProductConfigId:rvnHP:rn86E3:rvr95.36:cvnHP:ct10:cvrChassisVersion:sku1C4H8EA#ABZ:pfa103C_5335KVHPPavilion: dmi.product.family: 103C_5335KV HP Pavilion dmi.product.name: HP Pavilion Laptop 15-cs3xxx dmi.product.sku: 1C4H8EA#ABZ dmi.product.version: Type1ProductConfigId dmi.sys.vendor: HP --- ProblemType: Bug ApportVersion: 2.34.1-0ubuntu0.1 Architecture: amd64 CasperMD5CheckResult: unknown CurrentDesktop: KDE DistroRelease: Ubuntu 26.04 InstallationDate: Installed on 2026-05-19 (132 days ago) InstallationMedia: Kubuntu 26.04 "Resolute Raccoon" - Release amd64 (20260423) Lsusb: Bus 001 Device 001: ID 1d6b:0002 Linux Foundation 2.0 root hub Bus 001 Device 002: ID 04f2:b634 Chicony Electronics Co., Ltd HP Wide Vision FHD Camera Bus 001 Device 003: ID 8087:0aaa Intel Corp. Bluetooth 9460/9560 Jefferson Peak (JfP) Bus 002 Device 001: ID 1d6b:0003 Linux Foundation 3.0 root hub MachineType: HP HP Pavilion Laptop 15-cs3xxx NonfreeKernelModules: nvidia_modeset nvidia Package: linux (not installed) ProcFB: 0 i915drmfb ProcKernelCmdLine: BOOT_IMAGE=/boot/vmlinuz-7.0.0-34-generic root=UUID=f6336a40-bf4f-43f2-ab94-33cf9429e187 ro quiet splash pcie_aspm=off nvidia-drm.modeset=1 ProcVersionSignature: Ubuntu 7.0.0-34.34-generic 7.0.14 PulseList: Error: command ['pacmd', 'list'] failed with exit code 1: No PulseAudio daemon running, or not running as session daemon. Tags: resolute wayland-session Uname: Linux 7.0.0-34-generic x86_64 UpgradeStatus: No upgrade log present (probably fresh install) UserGroups: adm cdrom dip docker lpadmin ollama plugdev sambashare sudo wireshark _MarkForUpload: True dmi.bios.date: 08/23/2024 dmi.bios.release: 15.23 dmi.bios.vendor: Insyde dmi.bios.version: F.23 dmi.board.asset.tag: Type2 - Board Asset Tag dmi.board.name: 86E3 dmi.board.vendor: HP dmi.board.version: 95.36 dmi.chassis.asset.tag: Chassis Asset Tag dmi.chassis.type: 10 dmi.chassis.vendor: HP dmi.chassis.version: Chassis Version dmi.ec.firmware.release: 95.36 dmi.modalias: dmi:bvnInsyde:bvrF.23:bd08/23/2024:br15.23:efr95.36:svnHP:pnHPPavilionLaptop15-cs3xxx:pvrType1ProductConfigId:rvnHP:rn86E3:rvr95.36:cvnHP:ct10:cvrChassisVersion:sku1C4H8EA#ABZ:pfa103C_5335KVHPPavilion: dmi.product.family: 103C_5335KV HP Pavilion dmi.product.name: HP Pavilion Laptop 15-cs3xxx dmi.product.sku: 1C4H8EA#ABZ dmi.product.version: Type1ProductConfigId dmi.sys.vendor: HP --- ProblemType: Bug ApportVersion: 2.34.1-0ubuntu0.1 Architecture: amd64 CasperMD5CheckResult: unknown CurrentDesktop: KDE DistroRelease: Ubuntu 26.04 InstallationDate: Installed on 2026-05-19 (132 days ago) InstallationMedia: Kubuntu 26.04 "Resolute Raccoon" - Release amd64 (20260423) Lsusb: Bus 001 Device 001: ID 1d6b:0002 Linux Foundation 2.0 root hub Bus 001 Device 002: ID 04f2:b634 Chicony Electronics Co., Ltd HP Wide Vision FHD Camera Bus 001 Device 003: ID 8087:0aaa Intel Corp. Bluetooth 9460/9560 Jefferson Peak (JfP) Bus 002 Device 001: ID 1d6b:0003 Linux Foundation 3.0 root hub MachineType: HP HP Pavilion Laptop 15-cs3xxx NonfreeKernelModules: nvidia_modeset nvidia Package: linux-image-7.0.0-34-generic 7.0.0-34.34 PackageArchitecture: amd64 ProcFB: 0 i915drmfb ProcKernelCmdLine: BOOT_IMAGE=/boot/vmlinuz-7.0.0-34-generic root=UUID=f6336a40-bf4f-43f2-ab94-33cf9429e187 ro quiet splash pcie_aspm=off nvidia-drm.modeset=1 ProcVersionSignature: Ubuntu 7.0.0-34.34-generic 7.0.14 PulseList: Error: command ['pacmd', 'list'] failed with exit code 1: No PulseAudio daemon running, or not running as session daemon. Tags: resolute wayland-session Uname: Linux 7.0.0-34-generic x86_64 UpgradeStatus: No upgrade log present (probably fresh install) UserGroups: adm cdrom dip docker lpadmin ollama plugdev sambashare sudo wireshark _MarkForUpload: True dmi.bios.date: 08/23/2024 dmi.bios.release: 15.23 dmi.bios.vendor: Insyde dmi.bios.version: F.23 dmi.board.asset.tag: Type2 - Board Asset Tag dmi.board.name: 86E3 dmi.board.vendor: HP dmi.board.version: 95.36 dmi.chassis.asset.tag: Chassis Asset Tag dmi.chassis.type: 10 dmi.chassis.vendor: HP dmi.chassis.version: Chassis Version dmi.ec.firmware.release: 95.36 dmi.modalias: dmi:bvnInsyde:bvrF.23:bd08/23/2024:br15.23:efr95.36:svnHP:pnHPPavilionLaptop15-cs3xxx:pvrType1ProductConfigId:rvnHP:rn86E3:rvr95.36:cvnHP:ct10:cvrChassisVersion:sku1C4H8EA#ABZ:pfa103C_5335KVHPPavilion: dmi.product.family: 103C_5335KV HP Pavilion dmi.product.name: HP Pavilion Laptop 15-cs3xxx dmi.product.sku: 1C4H8EA#ABZ dmi.product.version: Type1ProductConfigId dmi.sys.vendor: HP To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/linux/+bug/2155632/+subscriptions

воскресенье

[Bug 2163121] Re: [Regression] Laptop fails to power off completely when HDMI is connected in kernel 7.0.0-28

Hi all, I can confirm that this issue affected my system when running kernels 7.0.0-31-generic and 7.0.0-34-generic on a Dell Pro laptop with AMD Radeon graphics. The primary symptom was that the system would become completely unresponsive during both restarts and full shutdown/startup cycles. The display would remain black and the system would not recover without a forced power reset. Recovery required holding the power button for approximately 30 seconds, waiting 5 seconds, and then pressing the power button again to start the system. This behaviour occurred during the majority of restart and power cycle operations. Following Krystian's recommendation to test 7.0.0-38-generic (although the referenced wiki page appears to be empty, so I used my own installation method), I found that the issue was completely resolved. To validate the fix, I performed: 10 full shutdown and power-on cycles 10 full system restarts In every test case, the system either restarted successfully or powered on normally with a single press of the power button. I was unable to reproduce the issue while running 7.0.0-38-generic. Please let me know if I can help with further information / logs, or if I can contribute to getting this proposed bugfix into "main" :-) My Rig is as follows: ### System Machine : Dell Pro 16 PC16255 (Dell Pro Laptops) Board : Dell Inc. 18G76C BIOS : 1.17.1 (07/31/2026) CPU : AMD Ryzen AI 7 350 w/ Radeon 860M, 16 threads, ucode 0xb600037 RAM : 30Gi GPU : AMD Radeon 860M [1002:1114] rev c2, driver: amdgpu GFX stack: mesa 25.2.8-0ubuntu0.24.04.2, linux-firmware 20240318.git3b128b60.0ubuntu3.1 ### Software OS : Ubuntu 24.04.5 LTS (amd64) Kernel : 7.0.0-38-generic (pkg 7.0.0-38.38~24.04.4) Previous: 7.0.0-34-generic Installed kernels: 7.0.0-31-generic 7.0.0-34-generic 7.0.0-38-generic Cmdline : BOOT_IMAGE=/vmlinuz-7.0.0-38-generic root=/dev/mapper/ubuntu--vg-ubuntu--lv ro quiet splash vt.handoff=7 Tainted : 0 Boot : UEFI, SecureBoot: enabled Session : wayland / KDE DKMS : none APT : proposed pocket enabled Cheers, Mike -- You received this bug notification because you are subscribed to linux in Ubuntu. Matching subscriptions: Bgg, Bmail, Nb https://bugs.launchpad.net/bugs/2163121 Title: [Regression] Laptop fails to power off completely when HDMI is connected in kernel 7.0.0-28 Status in linux package in Ubuntu: Fix Committed Status in linux-hwe-7.0 package in Ubuntu: Fix Committed Status in linux source package in Noble: Invalid Status in linux-hwe-7.0 source package in Noble: Fix Committed Status in linux source package in Resolute: Fix Committed Status in linux-hwe-7.0 source package in Resolute: Invalid Bug description: Issue Description: When shutting down the system with an external monitor connected via HDMI, the OS finishes the shutdown process normally, but the laptop hardware remains powered on (the power LED stays illuminated and the machine does not fully power off). If the HDMI cable is disconnected before the shutdown, the laptop powers off completely and correctly. Important note: Once the system enters this "stuck" state (black screen, power LED on), unplugging the HDMI cable does not recover the system or allow it to finish powering off. It remains completely frozen. The HDMI cable must be unplugged before initiating the shutdown sequence to avoid the hang. Additional troubleshooting: I have also tested this with two different HDMI cables to rule out a faulty cable, but the issue persists regardless of the cable used. Regression Details: This is a regression introduced in kernel 7.0.0-28. I have tested previous kernels on the exact same hardware and they work perfectly (the system powers off completely even with the HDMI connected). Fails in: Kernel 7.0.0-28-generic Works in: Kernel 7.0.0-14-generic, 6.x branch Steps to Reproduce: 1. Boot the laptop with kernel 7.0.0-28. 2, Connect an external monitor via the HDMI port. 3. Shut down the system from the GUI (or via sudo shutdown now). 4. Notice the OS halts, but the laptop's power LED remains on and the machine does not fully power down. 5. Unplugging the HDMI cable at this frozen stage does nothing; the machine remains stuck and must be forced off by holding the physical power button. System Information: OS: Linux Mint 22.3 Zena (Ubuntu 24.04 noble base) Hardware: LENOVO IdeaPad 5 15ALC05 CPU: AMD Ryzen 7 5700U with Radeon Graphics (Lucienne / Zen 2) GPU: AMD Lucienne (amdgpu driver) BIOS: H2CN33WW (08/30/2023) External Monitor: Xiaomi Monitor A22i (Model: A22FAB-RAGL) Hardware Details:   Kernel: 7.0.0-28-generic arch: x86_64 bits: 64 compiler: gcc v: 13.3.0 clocksource: tsc   Desktop: Cinnamon v: 6.6.9 tk: GTK v: 3.24.41 wm: Muffin v: 6.6.3 with: plank vt: 7 dm: LightDM     v: 1.30.0 Distro: Linux Mint 22.3 Zena base: Ubuntu 24.04 noble Machine:   Type: Laptop System: LENOVO product: 82LN v: IdeaPad 5 15ALC05   Mobo: LENOVO model: LNVNB161216 UEFI: LENOVO v: H2CN33WW date: 08/30/2023 CPU:   Info: 8-core model: AMD Ryzen 7 5700U with Radeon Graphics bits: 64 type: MT MCP smt: enabled     arch: Zen 2 rev: 1 Graphics:   Device-1: AMD Lucienne vendor: Lenovo driver: amdgpu v: kernel arch: GCN-5 pcie: speed: 8 GT/s     lanes: 16 ports: active: eDP-1 empty: DP-1,HDMI-A-1 bus-ID: 03:00.0 chip-ID: 1002:164c     class-ID: 0300 --- ProblemType: Bug ApportVersion: 2.28.3-0ubuntu0.1 Architecture: amd64 AudioDevicesInUse: USER PID ACCESS COMMAND /dev/snd/controlC1: user 1698 F.... wireplumber /dev/snd/controlC0: user 1698 F.... wireplumber /dev/snd/seq: user 1696 F.... pipewire CRDA: N/A CasperMD5CheckResult: pass CurrentDesktop: X-Cinnamon DistroRelease: Linux Mint 22.3 InstallationDate: Installed on 2026-07-22 (20 days ago) InstallationMedia: Linux Mint 22.3 "Zena" - Release amd64 20260108 MachineType: LENOVO 82LN Package: linux (not installed) ProcFB: 0 amdgpudrmfb ProcKernelCmdLine: BOOT_IMAGE=/vmlinuz-7.0.0-28-generic root=/dev/mapper/vgmint-root ro quiet splash ProcVersionSignature: Ubuntu 7.0.0-28.28~24.04.1-generic 7.0.12 PulseList: Error: command ['pacmd', 'list'] failed with exit code 1: No PulseAudio daemon running, or not running as session daemon. RelatedPackageVersions: linux-restricted-modules-7.0.0-28-generic N/A linux-backports-modules-7.0.0-28-generic N/A linux-firmware 20240318.git3b128b60-0ubuntu2.27 Tags: zena Uname: Linux 7.0.0-28-generic x86_64 UpgradeStatus: No upgrade log present (probably fresh install) UserGroups: adm cdrom dip kvm libvirt lpadmin plugdev sambashare sudo users _MarkForUpload: True dmi.bios.date: 08/30/2023 dmi.bios.release: 1.33 dmi.bios.vendor: LENOVO dmi.bios.version: H2CN33WW dmi.board.asset.tag: No Asset Tag dmi.board.name: LNVNB161216 dmi.board.vendor: LENOVO dmi.board.version: NO DPK dmi.chassis.asset.tag: No Asset Tag dmi.chassis.type: 10 dmi.chassis.vendor: LENOVO dmi.chassis.version: IdeaPad 5 15ALC05 dmi.ec.firmware.release: 1.33 dmi.modalias: dmi:bvnLENOVO:bvrH2CN33WW:bd08/30/2023:br1.33:efr1.33:svnLENOVO:pn82LN:pvrIdeaPad515ALC05:rvnLENOVO:rnLNVNB161216:rvrNODPK:cvnLENOVO:ct10:cvrIdeaPad515ALC05:skuLENOVO_MT_82LN_BU_idea_FM_IdeaPad515ALC05:pfaIdeaPad515ALC05: dmi.product.family: IdeaPad 5 15ALC05 dmi.product.name: 82LN dmi.product.sku: LENOVO_MT_82LN_BU_idea_FM_IdeaPad 5 15ALC05 dmi.product.version: IdeaPad 5 15ALC05 dmi.sys.vendor: LENOVO To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/linux/+bug/2163121/+subscriptions

[Bug 2168697] Re: linux (Noble): CIFS unmount use-after-free and panic introduced in 6.8.0-136 (CVE-2026-72315)

** Description changed: SRU Justification: [ Impact ] Noble 6.8.0-136 backported 340cea84f691 ("cifs: open files should not hold ref on superblock", v7.0) via LP: #2154496. Since then an open cifs file pins only its dentry, so umount(2) can complete while a read-ahead (cifs_readdata on cifsiod_wq), an uncached read/write (cifs_aio_ctx) or a writeback (cifs_writedata) still owns a cifsFileInfo. generic_shutdown_super() finds the inode busy, poisons i_sb with VFS_PTR_POISON, and the later _cifsFileInfo_put() from cifs_readahead_complete() faults on 0xdead0000000000f5 + 0x390. With panic_on_oops=1 the host panics; with panic_on_oops=0 every later umount of a cifs filesystem hangs forever in cifs_kill_sb(). Workloads that mount and unmount SMB shares while a reader is killed (containers, per-job mounts) can hit it. 6.8.0-139 (LP: #2160250) added c68337442f03 ("cifs: Fix busy dentry used after unmounting"), which flushes deferredclose_wq only and covers the deferred-close variant (1 of our 9 production panics). The read-ahead variant (8 of 9) is fixed upstream by 75f5c412fa86 ("smb: client: fix busy dentry warning on unmount after DIO", v7.2, CVE-2026-72315), which is in no Noble 6.8 kernel up to 6.8.0-146 and does not apply as-is because the 6.8 cifs read/write path predates the netfs conversion. Observed: 6.8.0-137 (9 panics / 8 hosts / 30 h on ~850 hosts; lab reproducer panics in 5-90 s) and 6.8.0-146 (lab, ~10 s). Not affected: 6.8.0-111 (same workload, ~3,800 hosts, 0 in 17 days). [ Fix ] Backport of 75f5c412fa86 to the pre-netfs 6.8 code: a per-superblock counter (cifs_sb->outstanding_rreq, as upstream) is taken where a cifs_readdata / cifs_writedata / cifs_aio_ctx acquires its cifsFileInfo reference (including the two writeback sites that transfer an already-held reference) and released after the put in the three release functions. cifs_kill_sb() waits for the counter to reach zero, then flushes serverclose_wq and fileinfo_put_wq before kill_anon_super(), exactly as upstream. A flush-only alternative (flush cifsiod_wq, serverclose_wq, fileinfo_put_wq) was built and tested and still panics: the read request is still on the socket when umount runs, so there is nothing queued to flush. [ Test Plan ] Mount an SMB3 share, start a sequential read of a 2-3 MB file (read-ahead queued), SIGKILL the reader after 1-90 ms, open/close another file, umount immediately; repeat in 4-8 parallel workers on separate mount points (script attached). Stock 6.8.0-137 panics within ~90 s at 8 workers; stock 6.8.0-146 within ~10 s. With the patch on 6.8.0-146.146: ~76,000 cycles against a Dell PowerScale (Isilon) share (krb5, ro) and a Samba share (ro and rw, buffered and O_DIRECT writers, 40-150 ms added server delay) with 0 "Dentry still in use" warnings, 0 faults, 0 hung umounts. We can test a -proposed kernel within minutes. [ Where problems could occur ] The change is confined to fs/smb/client. The counter must balance at every cifsFileInfo acquisition and release of cifs_readdata, cifs_writedata and cifs_aio_ctx; an unbalanced path would make umount(2) wait forever in cifs_kill_sb() (an earlier revision of this port missed the two writeback transfer sites; code review caught it before any write test, which is why they are counted explicitly and the write path was tested separately). The wait runs only at unmount, after the VFS has detached the superblock, so no new I/O can start on it; steady-state I/O paths gain one atomic increment and decrement per request. [ Other Info ] Related but separate: 5520e89a5a4f ("smb: client: fix cifsFileInfo reference leak in deferred close") fixes a refcount leak with a different Fixes: tag; it is not part of this bug. == Evidence (details) == Release: Ubuntu 24.04 LTS (Noble) Package: linux, tested at 6.8.0-137.137 and 6.8.0-146.146 Expected: umount(2) returns and the host continues running. Actual: _cifsFileInfo_put() dereferences an inode after superblock teardown and faults. The host panics with panic_on_oops=1, or later CIFS unmounts hang with panic_on_oops=0. Affected kernels: * Tested: 6.8.0-137.137. We saw 9 production panics on 8 hosts in about - 30 hours across about 850 nodes. The lab reproducer panics in 5–90 seconds. +   30 hours across about 850 nodes. The lab reproducer panics in 5–90 seconds. * Tested: 6.8.0-146.146 (noble-proposed). The lab reproducer panics in about - 10 seconds. +   10 seconds. * Code-inferred: 6.8.0-136.136, which introduced 340cea84f691c, and - 6.8.0-138.138, which predates c68337442f03. +   6.8.0-138.138, which predates c68337442f03. * Partial fix from 6.8.0-139.139: c68337442f03 flushes deferredclose_wq only. * Not affected: 6.8.0-111.111. The same workload ran on about 3,800 nodes - for 17 days without an occurrence. This kernel predates 340cea84f691c. +   for 17 days without an occurrence. This kernel predates 340cea84f691c. == Summary == Noble 6.8.0-136 introduced upstream 340cea84f691c ("cifs: open files should not hold ref on superblock", mainline v7.0) via the upstream-stable patchset tracked by LP: #2154496. After this change, a cifs open file holds only a dentry reference. umount(2) can complete while asynchronous work still owns a cifsFileInfo. When that work later calls _cifsFileInfo_put(), the superblock is gone and the kernel faults on the VFS_PTR_POISON value written into the surviving inode. We observed these paths: * (a) deferredclose: smb2_deferred_work_close -> _cifsFileInfo_put. - Fixed by c68337442f03 in 6.8.0-139 and later. +   Fixed by c68337442f03 in 6.8.0-139 and later. * (b) cifsiod: cifs_readahead_complete -> _cifsFileInfo_put. - Not fixed in any Noble 6.8 kernel through 6.8.0-146. +   Not fixed in any Noble 6.8 kernel through 6.8.0-146. * (c) cifsoplockd: cifs_oplock_break -> _cifsFileInfo_put. - This secondary path appeared only after path (b) had already oopsed with - panic_on_oops=0. We have not demonstrated it as an independent race. +   This secondary path appeared only after path (b) had already oopsed with +   panic_on_oops=0. We have not demonstrated it as an independent race. In production on 6.8.0-137, path (b) caused 8 panics and path (a) caused 1. On 6.8.0-146 the reproducer triggers path (b), followed by path (c) when panic_on_oops=0. The proposed fix eliminated this complete reproduced sequence. We do not claim that it fixes a separate oplock race. == Impact == With panic_on_oops=1, the whole host panics. With panic_on_oops=0, the oopsed kworkers do not complete and later CIFS unmounts hang in D state at: - __flush_workqueue <- cifs_kill_sb +   __flush_workqueue <- cifs_kill_sb Workloads that mount and unmount SMB shares for each job, such as container workloads, exercise this path continuously. == Kernel log, variant (b) — 6.8.0-137-generic #137-Ubuntu, production == [24042.343670] BUG: Dentry 000000002c909471{i=c34b9,n=<file>} still in use (1) [unmount of cifs cifs] [24042.343678] WARNING: CPU: 28 PID: 1352709 at fs/dcache.c:1528 umount_check+0x64/0x90 [24042.343780] CPU: 28 PID: 1352709 Comm: umount Kdump: loaded Tainted: P OE 6.8.0-137-generic #137-Ubuntu [24042.343783] RIP: 0010:umount_check+0x64/0x90 [24042.343802] d_walk+0xc0/0x2a0 [24042.343810] generic_shutdown_super+0x21/0x180 [24042.343815] cifs_kill_sb+0x5b/0x70 [cifs] [24042.343853] cleanup_mnt+0xc3/0x170 [24042.343938] WARNING: CPU: 28 PID: 1352709 at fs/super.c:649 generic_shutdown_super+0x120/0x180 - VFS: Busy inodes after unmount of cifs (cifs) +                VFS: Busy inodes after unmount of cifs (cifs) [24043.843507] general protection fault, probably for non-canonical address 0xdead000000000485: 0000 [#1] PREEMPT SMP NOPTI [24043.854484] CPU: 4 PID: 1352168 Comm: kworker/4:1 Kdump: loaded Tainted: P W OE 6.8.0-137-generic #137-Ubuntu [24043.875232] Workqueue: cifsiod cifs_readahead_complete [cifs] [24043.881106] RIP: 0010:_cifsFileInfo_put+0x77/0x4a0 [cifs] [24043.910734] RAX: dead0000000000f5 RBX: ffff8e6ee73a1ea8 RCX: 000000000000000a [24043.983676] cifs_readahead_complete+0x23e/0x2f0 [cifs] [24043.988976] process_one_work+0x181/0x3a0 [24043.993014] worker_thread+0x18b/0x330 [24044.001087] kthread+0xef/0x120 [24044.245052] Kernel panic - not syncing: Fatal exception == Kernel log, variant (a) — 6.8.0-137, production == [17180.976882] BUG: Dentry 00000000e23b32d6{i=34fc,n=<file>} still in use (1) [unmount of cifs cifs] [17180.977008] RIP: 0010:umount_check+0x64/0x90 [17180.977052] cifs_kill_sb+0x5b/0x70 [cifs] [17180.977268] VFS: Busy inodes after unmount of cifs (cifs) [17181.900781] Workqueue: deferredclose smb2_deferred_work_close [cifs] [17181.907243] RIP: 0010:_raw_spin_lock+0x13/0x60 [17182.014078] cifsFileInfo_put_final+0xed/0x120 [cifs] [17182.019221] _cifsFileInfo_put+0x350/0x4a0 [cifs] [17182.028127] smb2_deferred_work_close+0x5f/0x70 [cifs] - Kernel panic - not syncing: Fatal exception +                Kernel panic - not syncing: Fatal exception == Kernel log, variants (b) and (c) == Kernel: 6.8.0-146-generic #146-Ubuntu, lab, panic_on_oops=0 [ 142.574284] general protection fault, probably for non-canonical address 0xdead000000000485: 0000 [#1] PREEMPT SMP NOPTI [ 142.605742] Workqueue: cifsiod cifs_readahead_complete [cifs] [ 142.611633] RIP: 0010:_cifsFileInfo_put+0x77/0x4a0 [cifs] [ 142.857981] general protection fault, probably for non-canonical address 0xdead000000000485: 0000 [#2] PREEMPT SMP NOPTI [ 142.868925] Workqueue: cifsoplockd cifs_oplock_break [cifs] [ 142.868997] RIP: 0010:cifs_oplock_break+0x43/0x620 [cifs] [ 142.888932] RIP: 0010:_cifsFileInfo_put+0x77/0x4a0 [cifs] (preceded by "BUG: Dentry ... still in use (1) [unmount of cifs cifs]" from umount_check) Afterwards on 6.8.0-146: 8 umount processes in D state, all at - __flush_workqueue+0x14a/0x3e0 - <- cifs_kill_sb+0x3c/0x70 [cifs] - <- deactivate_locked_super - <- cleanup_mnt +   __flush_workqueue+0x14a/0x3e0 +   <- cifs_kill_sb+0x3c/0x70 [cifs] +   <- deactivate_locked_super +   <- cleanup_mnt == vmcore analysis (6.8.0-146.146, variant b) == Analysis used crash with linux-image-unsigned-6.8.0-146-generic-dbgsym. The faulting instruction at _cifsFileInfo_put+0x77 is the inlined CIFS_SB(inode->i_sb), which reads sb->s_fs_info at offset 0x390. The inode is d_inode(cifs_file->dentry). Objects in the dump: * inode ffff8bb592233680: - i_ino=0xec6, matching the "i=ec6" umount_check line; i_nlink=1; - i_count=1; i_state=0; still on sb->s_inodes; and - i_op = i_sb = i_mapping = 0xdead0000000000f5 (VFS_PTR_POISON). +   i_ino=0xec6, matching the "i=ec6" umount_check line; i_nlink=1; +   i_count=1; i_state=0; still on sb->s_inodes; and +   i_op = i_sb = i_mapping = 0xdead0000000000f5 (VFS_PTR_POISON). * dentry ffff8bb5861c7380: - "<file>"; d_lockref.count=1, held by the cifsFileInfo. +   "<file>"; d_lockref.count=1, held by the cifsFileInfo. * superblock ffff8ab5ae3e9800: - type "cifs"; s_count=0; s_active=0; s_root=NULL. +   type "cifs"; s_count=0; s_active=0; s_root=NULL. * cifsFileInfo ffff8bb551338a00: - allocated from kmalloc-512. +   allocated from kmalloc-512. * cifs_tcon ffff8ab51c791800: - allocated. +   allocated. generic_shutdown_super() writes this VFS_PTR_POISON value when CHECK_DATA_CORRUPTION(!list_empty(&sb->s_inodes), "VFS: Busy inodes after unmount") fires at fs/super.c:649-663. The read-ahead cifsFileInfo kept the dentry and inode alive across unmount. The superblock was torn down, and the completion work then dereferenced inode->i_sb. This matches the mechanism addressed by 75f5c412fa86: wait for in-flight requests and drain final-put work before kill_anon_super(). The deferredclose_wq flush from c68337442f03 does not cover cifsiod or cifsoplockd work. The vmcore and vmlinux are available on request. == Reproducer (lab, both 6.8.0-137 and 6.8.0-146) == Server: Dell PowerScale (Isilon) SMB3 share, mounted read-only with - -o vers=3.0,sec=krb5,dir_mode=0755,file_mode=0755,noperm, - noserverino,nosharesock,cruid=0,nobrl,ro +   -o vers=3.0,sec=krb5,dir_mode=0755,file_mode=0755,noperm, +      noserverino,nosharesock,cruid=0,nobrl,ro mount.cifs reports: - cache=strict,soft,nounix,mapposix,rsize=1048576,wsize=1048576 +   cache=strict,soft,nounix,mapposix,rsize=1048576,wsize=1048576 Loop, N parallel workers, each on its own mount point: 1. Mount the share. 2. Start a sequential read, which queues read-ahead: - dd if=<2–3 MB file on the share> of=/dev/null bs=1M & +      dd if=<2–3 MB file on the share> of=/dev/null bs=1M & 3. Sleep for 0.01–0.09 seconds, then kill the dd process while I/O is in - flight. +    flight. 4. Open and close another file to leave a deferred close pending: - head -c 65536 <another file> >/dev/null +      head -c 65536 <another file> >/dev/null 5. Immediately unmount the mount point. 6. Repeat. Results: * 6.8.0-137, 8 workers: panic within about 90 seconds (variant b), with a - kdump fingerprint on the BMC. +   kdump fingerprint on the BMC. * 6.8.0-137, 4 workers, panic_on_oops=0: oops (b), then (c), within about - 5 seconds. +   5 seconds. * 6.8.0-146, 4 workers for 45 seconds: 5 "Dentry ... still in use" - warnings and no fault. +   warnings and no fault. * 6.8.0-146, 8 workers: oops (b), then (c), within about 10 seconds. The "still in use" warning occurs several times per minute with 4 workers on 6.8.0-146. The fault requires the deferred work to run after the superblock is freed, so it becomes more likely with parallel workers. == Regression boundary (from the Noble changelog) == * linux 6.8.0-136.136, "Noble update: upstream stable patchset 2026-05-28" - (LP: #2154496), added: - - 340cea84f691c (v7.0) - cifs: open files should not hold ref on superblock +   (LP: #2154496), added: + +     340cea84f691c (v7.0) +     cifs: open files should not hold ref on superblock * linux 6.8.0-139.139, "Noble update: upstream stable patchset 2026-07-09" - (LP: #2160250), added: - - c68337442f03 (v7.1, Cc: stable, Fixes: 340cea84f691c) - cifs: Fix busy dentry used after unmounting - - This commit adds flush_workqueue(deferredclose_wq) in cifs_kill_sb(). It - covers variant (a) only. +   (LP: #2160250), added: + +     c68337442f03 (v7.1, Cc: stable, Fixes: 340cea84f691c) +     cifs: Fix busy dentry used after unmounting + +   This commit adds flush_workqueue(deferredclose_wq) in cifs_kill_sb(). It +   covers variant (a) only. * No Noble 6.8 kernel through 6.8.0-146.146 contains: - 75f5c412fa86 (v7.2, Fixes: 340cea84f691c) - smb: client: fix busy dentry warning on unmount after DIO - - This commit adds cifs_sb->outstanding_rreq, waits for in-flight requests, - and flushes serverclose_wq and fileinfo_put_wq before kill_anon_super(). - This is the mechanism that covers variants (b) and (c). +     75f5c412fa86 (v7.2, Fixes: 340cea84f691c) +     smb: client: fix busy dentry warning on unmount after DIO + +   This commit adds cifs_sb->outstanding_rreq, waits for in-flight requests, +   and flushes serverclose_wq and fileinfo_put_wq before kill_anon_super(). +   This is the mechanism that covers variants (b) and (c). == Request == Track this under CVE-2026-72315, the outstanding-I/O defect fixed by 75f5c412fa86. 1. Apply the attached Noble 6.8 backport of 75f5c412fa86. Noble predates - the cifs netfs conversion, so the backport accounts for the cifsFileInfo - references held by cifs_readdata, cifs_writedata and cifs_aio_ctx instead - of netfs requests. cifs_kill_sb() waits for that per-superblock count to - reach zero, then flushes serverclose_wq and fileinfo_put_wq before - kill_anon_super(). The patch survived about 76,000 tested cycles. The - flush-only alternative still panicked within about 30 seconds with the - same cifsiod/cifs_readahead_complete trace. +    the cifs netfs conversion, so the backport accounts for the cifsFileInfo +    references held by cifs_readdata, cifs_writedata and cifs_aio_ctx instead +    of netfs requests. cifs_kill_sb() waits for that per-superblock count to +    reach zero, then flushes serverclose_wq and fileinfo_put_wq before +    kill_anon_super(). The patch survived about 76,000 tested cycles. The +    flush-only alternative still panicked within about 30 seconds with the +    same cifsiod/cifs_readahead_complete trace. 2. We can validate a candidate kernel within minutes with the attached - reproducer. +    reproducer. 3. Consider noting in the 6.8.0-136, 6.8.0-137 and 6.8.0-138 release notes - that 340cea84f691c shipped without its stable follow-up c68337442f03. +    that 340cea84f691c shipped without its stable follow-up c68337442f03. Related but separate: 5520e89a5a4f ("smb: client: fix cifsFileInfo reference leak in deferred close", Fixes: c3f207ab29f7) fixes a refcount leak when queue_delayed_work() finds work already pending. It has a different Fixes commit and is not asserted to cause this panic. Please track it separately. == Environment / attachments == Ubuntu 24.04 (Noble), x86_64, HPE ProLiant XL225n Gen10 Plus, in-tree cifs.ko 2.47, and SMB3 to Dell PowerScale. Production mounts and unmounts the share for each cri-o container lifecycle. The lab uses a hand-driven loop. - Attached evidence: - - * Production panic context and kworker trace. - * Firmware pstore record from a lab 6.8.0-137 panic. - * Live and vmcore dmesg from stock 6.8.0-146. - * Vmcore analysis. - * Reproducer. - * Version, PCI, release and package metadata. - * Tested SRU patch. /proc/version_signature reported: - Ubuntu 6.8.0-137.137-generic 6.8.12 - Ubuntu 6.8.0-146.146-generic 6.8.12 +   Ubuntu 6.8.0-137.137-generic 6.8.12 +   Ubuntu 6.8.0-146.146-generic 6.8.12 A 3.4 GB kdump vmcore of the 6.8.0-146.146 variant-(b) panic was captured on 2026-09-27 with makedumpfile -c -d 31. It is available on request with - the matching vmlinux. Its dmesg and object analysis are attached. + the matching vmlinux. Its dmesg is attached. -- You received this bug notification because you are subscribed to linux in Ubuntu. Matching subscriptions: Bgg, Bmail, Nb https://bugs.launchpad.net/bugs/2168697 Title: linux (Noble): CIFS unmount use-after-free and panic introduced in 6.8.0-136 (CVE-2026-72315) Status in linux package in Ubuntu: New Bug description: SRU Justification: [ Impact ] Noble 6.8.0-136 backported 340cea84f691 ("cifs: open files should not hold ref on superblock", v7.0) via LP: #2154496. Since then an open cifs file pins only its dentry, so umount(2) can complete while a read-ahead (cifs_readdata on cifsiod_wq), an uncached read/write (cifs_aio_ctx) or a writeback (cifs_writedata) still owns a cifsFileInfo. generic_shutdown_super() finds the inode busy, poisons i_sb with VFS_PTR_POISON, and the later _cifsFileInfo_put() from cifs_readahead_complete() faults on 0xdead0000000000f5 + 0x390. With panic_on_oops=1 the host panics; with panic_on_oops=0 every later umount of a cifs filesystem hangs forever in cifs_kill_sb(). Workloads that mount and unmount SMB shares while a reader is killed (containers, per-job mounts) can hit it. 6.8.0-139 (LP: #2160250) added c68337442f03 ("cifs: Fix busy dentry used after unmounting"), which flushes deferredclose_wq only and covers the deferred-close variant (1 of our 9 production panics). The read-ahead variant (8 of 9) is fixed upstream by 75f5c412fa86 ("smb: client: fix busy dentry warning on unmount after DIO", v7.2, CVE-2026-72315), which is in no Noble 6.8 kernel up to 6.8.0-146 and does not apply as-is because the 6.8 cifs read/write path predates the netfs conversion. Observed: 6.8.0-137 (9 panics / 8 hosts / 30 h on ~850 hosts; lab reproducer panics in 5-90 s) and 6.8.0-146 (lab, ~10 s). Not affected: 6.8.0-111 (same workload, ~3,800 hosts, 0 in 17 days). [ Fix ] Backport of 75f5c412fa86 to the pre-netfs 6.8 code: a per-superblock counter (cifs_sb->outstanding_rreq, as upstream) is taken where a cifs_readdata / cifs_writedata / cifs_aio_ctx acquires its cifsFileInfo reference (including the two writeback sites that transfer an already-held reference) and released after the put in the three release functions. cifs_kill_sb() waits for the counter to reach zero, then flushes serverclose_wq and fileinfo_put_wq before kill_anon_super(), exactly as upstream. A flush-only alternative (flush cifsiod_wq, serverclose_wq, fileinfo_put_wq) was built and tested and still panics: the read request is still on the socket when umount runs, so there is nothing queued to flush. [ Test Plan ] Mount an SMB3 share, start a sequential read of a 2-3 MB file (read-ahead queued), SIGKILL the reader after 1-90 ms, open/close another file, umount immediately; repeat in 4-8 parallel workers on separate mount points (script attached). Stock 6.8.0-137 panics within ~90 s at 8 workers; stock 6.8.0-146 within ~10 s. With the patch on 6.8.0-146.146: ~76,000 cycles against a Dell PowerScale (Isilon) share (krb5, ro) and a Samba share (ro and rw, buffered and O_DIRECT writers, 40-150 ms added server delay) with 0 "Dentry still in use" warnings, 0 faults, 0 hung umounts. We can test a -proposed kernel within minutes. [ Where problems could occur ] The change is confined to fs/smb/client. The counter must balance at every cifsFileInfo acquisition and release of cifs_readdata, cifs_writedata and cifs_aio_ctx; an unbalanced path would make umount(2) wait forever in cifs_kill_sb() (an earlier revision of this port missed the two writeback transfer sites; code review caught it before any write test, which is why they are counted explicitly and the write path was tested separately). The wait runs only at unmount, after the VFS has detached the superblock, so no new I/O can start on it; steady-state I/O paths gain one atomic increment and decrement per request. [ Other Info ] Related but separate: 5520e89a5a4f ("smb: client: fix cifsFileInfo reference leak in deferred close") fixes a refcount leak with a different Fixes: tag; it is not part of this bug. == Evidence (details) == Release: Ubuntu 24.04 LTS (Noble) Package: linux, tested at 6.8.0-137.137 and 6.8.0-146.146 Expected: umount(2) returns and the host continues running. Actual: _cifsFileInfo_put() dereferences an inode after superblock teardown and faults. The host panics with panic_on_oops=1, or later CIFS unmounts hang with panic_on_oops=0. Affected kernels: * Tested: 6.8.0-137.137. We saw 9 production panics on 8 hosts in about   30 hours across about 850 nodes. The lab reproducer panics in 5–90 seconds. * Tested: 6.8.0-146.146 (noble-proposed). The lab reproducer panics in about   10 seconds. * Code-inferred: 6.8.0-136.136, which introduced 340cea84f691c, and   6.8.0-138.138, which predates c68337442f03. * Partial fix from 6.8.0-139.139: c68337442f03 flushes deferredclose_wq only. * Not affected: 6.8.0-111.111. The same workload ran on about 3,800 nodes   for 17 days without an occurrence. This kernel predates 340cea84f691c. == Summary == Noble 6.8.0-136 introduced upstream 340cea84f691c ("cifs: open files should not hold ref on superblock", mainline v7.0) via the upstream-stable patchset tracked by LP: #2154496. After this change, a cifs open file holds only a dentry reference. umount(2) can complete while asynchronous work still owns a cifsFileInfo. When that work later calls _cifsFileInfo_put(), the superblock is gone and the kernel faults on the VFS_PTR_POISON value written into the surviving inode. We observed these paths: * (a) deferredclose: smb2_deferred_work_close -> _cifsFileInfo_put.   Fixed by c68337442f03 in 6.8.0-139 and later. * (b) cifsiod: cifs_readahead_complete -> _cifsFileInfo_put.   Not fixed in any Noble 6.8 kernel through 6.8.0-146. * (c) cifsoplockd: cifs_oplock_break -> _cifsFileInfo_put.   This secondary path appeared only after path (b) had already oopsed with   panic_on_oops=0. We have not demonstrated it as an independent race. In production on 6.8.0-137, path (b) caused 8 panics and path (a) caused 1. On 6.8.0-146 the reproducer triggers path (b), followed by path (c) when panic_on_oops=0. The proposed fix eliminated this complete reproduced sequence. We do not claim that it fixes a separate oplock race. == Impact == With panic_on_oops=1, the whole host panics. With panic_on_oops=0, the oopsed kworkers do not complete and later CIFS unmounts hang in D state at:   __flush_workqueue <- cifs_kill_sb Workloads that mount and unmount SMB shares for each job, such as container workloads, exercise this path continuously. == Kernel log, variant (b) — 6.8.0-137-generic #137-Ubuntu, production == [24042.343670] BUG: Dentry 000000002c909471{i=c34b9,n=<file>} still in use (1) [unmount of cifs cifs] [24042.343678] WARNING: CPU: 28 PID: 1352709 at fs/dcache.c:1528 umount_check+0x64/0x90 [24042.343780] CPU: 28 PID: 1352709 Comm: umount Kdump: loaded Tainted: P OE 6.8.0-137-generic #137-Ubuntu [24042.343783] RIP: 0010:umount_check+0x64/0x90 [24042.343802] d_walk+0xc0/0x2a0 [24042.343810] generic_shutdown_super+0x21/0x180 [24042.343815] cifs_kill_sb+0x5b/0x70 [cifs] [24042.343853] cleanup_mnt+0xc3/0x170 [24042.343938] WARNING: CPU: 28 PID: 1352709 at fs/super.c:649 generic_shutdown_super+0x120/0x180                VFS: Busy inodes after unmount of cifs (cifs) [24043.843507] general protection fault, probably for non-canonical address 0xdead000000000485: 0000 [#1] PREEMPT SMP NOPTI [24043.854484] CPU: 4 PID: 1352168 Comm: kworker/4:1 Kdump: loaded Tainted: P W OE 6.8.0-137-generic #137-Ubuntu [24043.875232] Workqueue: cifsiod cifs_readahead_complete [cifs] [24043.881106] RIP: 0010:_cifsFileInfo_put+0x77/0x4a0 [cifs] [24043.910734] RAX: dead0000000000f5 RBX: ffff8e6ee73a1ea8 RCX: 000000000000000a [24043.983676] cifs_readahead_complete+0x23e/0x2f0 [cifs] [24043.988976] process_one_work+0x181/0x3a0 [24043.993014] worker_thread+0x18b/0x330 [24044.001087] kthread+0xef/0x120 [24044.245052] Kernel panic - not syncing: Fatal exception == Kernel log, variant (a) — 6.8.0-137, production == [17180.976882] BUG: Dentry 00000000e23b32d6{i=34fc,n=<file>} still in use (1) [unmount of cifs cifs] [17180.977008] RIP: 0010:umount_check+0x64/0x90 [17180.977052] cifs_kill_sb+0x5b/0x70 [cifs] [17180.977268] VFS: Busy inodes after unmount of cifs (cifs) [17181.900781] Workqueue: deferredclose smb2_deferred_work_close [cifs] [17181.907243] RIP: 0010:_raw_spin_lock+0x13/0x60 [17182.014078] cifsFileInfo_put_final+0xed/0x120 [cifs] [17182.019221] _cifsFileInfo_put+0x350/0x4a0 [cifs] [17182.028127] smb2_deferred_work_close+0x5f/0x70 [cifs]                Kernel panic - not syncing: Fatal exception == Kernel log, variants (b) and (c) == Kernel: 6.8.0-146-generic #146-Ubuntu, lab, panic_on_oops=0 [ 142.574284] general protection fault, probably for non-canonical address 0xdead000000000485: 0000 [#1] PREEMPT SMP NOPTI [ 142.605742] Workqueue: cifsiod cifs_readahead_complete [cifs] [ 142.611633] RIP: 0010:_cifsFileInfo_put+0x77/0x4a0 [cifs] [ 142.857981] general protection fault, probably for non-canonical address 0xdead000000000485: 0000 [#2] PREEMPT SMP NOPTI [ 142.868925] Workqueue: cifsoplockd cifs_oplock_break [cifs] [ 142.868997] RIP: 0010:cifs_oplock_break+0x43/0x620 [cifs] [ 142.888932] RIP: 0010:_cifsFileInfo_put+0x77/0x4a0 [cifs] (preceded by "BUG: Dentry ... still in use (1) [unmount of cifs cifs]" from umount_check) Afterwards on 6.8.0-146: 8 umount processes in D state, all at   __flush_workqueue+0x14a/0x3e0   <- cifs_kill_sb+0x3c/0x70 [cifs]   <- deactivate_locked_super   <- cleanup_mnt == vmcore analysis (6.8.0-146.146, variant b) == Analysis used crash with linux-image-unsigned-6.8.0-146-generic-dbgsym. The faulting instruction at _cifsFileInfo_put+0x77 is the inlined CIFS_SB(inode->i_sb), which reads sb->s_fs_info at offset 0x390. The inode is d_inode(cifs_file->dentry). Objects in the dump: * inode ffff8bb592233680:   i_ino=0xec6, matching the "i=ec6" umount_check line; i_nlink=1;   i_count=1; i_state=0; still on sb->s_inodes; and   i_op = i_sb = i_mapping = 0xdead0000000000f5 (VFS_PTR_POISON). * dentry ffff8bb5861c7380:   "<file>"; d_lockref.count=1, held by the cifsFileInfo. * superblock ffff8ab5ae3e9800:   type "cifs"; s_count=0; s_active=0; s_root=NULL. * cifsFileInfo ffff8bb551338a00:   allocated from kmalloc-512. * cifs_tcon ffff8ab51c791800:   allocated. generic_shutdown_super() writes this VFS_PTR_POISON value when CHECK_DATA_CORRUPTION(!list_empty(&sb->s_inodes), "VFS: Busy inodes after unmount") fires at fs/super.c:649-663. The read-ahead cifsFileInfo kept the dentry and inode alive across unmount. The superblock was torn down, and the completion work then dereferenced inode->i_sb. This matches the mechanism addressed by 75f5c412fa86: wait for in-flight requests and drain final-put work before kill_anon_super(). The deferredclose_wq flush from c68337442f03 does not cover cifsiod or cifsoplockd work. The vmcore and vmlinux are available on request. == Reproducer (lab, both 6.8.0-137 and 6.8.0-146) == Server: Dell PowerScale (Isilon) SMB3 share, mounted read-only with   -o vers=3.0,sec=krb5,dir_mode=0755,file_mode=0755,noperm,      noserverino,nosharesock,cruid=0,nobrl,ro mount.cifs reports:   cache=strict,soft,nounix,mapposix,rsize=1048576,wsize=1048576 Loop, N parallel workers, each on its own mount point: 1. Mount the share. 2. Start a sequential read, which queues read-ahead:      dd if=<2–3 MB file on the share> of=/dev/null bs=1M & 3. Sleep for 0.01–0.09 seconds, then kill the dd process while I/O is in    flight. 4. Open and close another file to leave a deferred close pending:      head -c 65536 <another file> >/dev/null 5. Immediately unmount the mount point. 6. Repeat. Results: * 6.8.0-137, 8 workers: panic within about 90 seconds (variant b), with a   kdump fingerprint on the BMC. * 6.8.0-137, 4 workers, panic_on_oops=0: oops (b), then (c), within about   5 seconds. * 6.8.0-146, 4 workers for 45 seconds: 5 "Dentry ... still in use"   warnings and no fault. * 6.8.0-146, 8 workers: oops (b), then (c), within about 10 seconds. The "still in use" warning occurs several times per minute with 4 workers on 6.8.0-146. The fault requires the deferred work to run after the superblock is freed, so it becomes more likely with parallel workers. == Regression boundary (from the Noble changelog) == * linux 6.8.0-136.136, "Noble update: upstream stable patchset 2026-05-28"   (LP: #2154496), added:     340cea84f691c (v7.0)     cifs: open files should not hold ref on superblock * linux 6.8.0-139.139, "Noble update: upstream stable patchset 2026-07-09"   (LP: #2160250), added:     c68337442f03 (v7.1, Cc: stable, Fixes: 340cea84f691c)     cifs: Fix busy dentry used after unmounting   This commit adds flush_workqueue(deferredclose_wq) in cifs_kill_sb(). It   covers variant (a) only. * No Noble 6.8 kernel through 6.8.0-146.146 contains:     75f5c412fa86 (v7.2, Fixes: 340cea84f691c)     smb: client: fix busy dentry warning on unmount after DIO   This commit adds cifs_sb->outstanding_rreq, waits for in-flight requests,   and flushes serverclose_wq and fileinfo_put_wq before kill_anon_super().   This is the mechanism that covers variants (b) and (c). == Request == Track this under CVE-2026-72315, the outstanding-I/O defect fixed by 75f5c412fa86. 1. Apply the attached Noble 6.8 backport of 75f5c412fa86. Noble predates    the cifs netfs conversion, so the backport accounts for the cifsFileInfo    references held by cifs_readdata, cifs_writedata and cifs_aio_ctx instead    of netfs requests. cifs_kill_sb() waits for that per-superblock count to    reach zero, then flushes serverclose_wq and fileinfo_put_wq before    kill_anon_super(). The patch survived about 76,000 tested cycles. The    flush-only alternative still panicked within about 30 seconds with the    same cifsiod/cifs_readahead_complete trace. 2. We can validate a candidate kernel within minutes with the attached    reproducer. 3. Consider noting in the 6.8.0-136, 6.8.0-137 and 6.8.0-138 release notes    that 340cea84f691c shipped without its stable follow-up c68337442f03. Related but separate: 5520e89a5a4f ("smb: client: fix cifsFileInfo reference leak in deferred close", Fixes: c3f207ab29f7) fixes a refcount leak when queue_delayed_work() finds work already pending. It has a different Fixes commit and is not asserted to cause this panic. Please track it separately. == Environment / attachments == Ubuntu 24.04 (Noble), x86_64, HPE ProLiant XL225n Gen10 Plus, in-tree cifs.ko 2.47, and SMB3 to Dell PowerScale. Production mounts and unmounts the share for each cri-o container lifecycle. The lab uses a hand-driven loop. /proc/version_signature reported:   Ubuntu 6.8.0-137.137-generic 6.8.12   Ubuntu 6.8.0-146.146-generic 6.8.12 A 3.4 GB kdump vmcore of the 6.8.0-146.146 variant-(b) panic was captured on 2026-09-27 with makedumpfile -c -d 31. It is available on request with the matching vmlinux. Its dmesg is attached. To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/linux/+bug/2168697/+subscriptions

[Bug 2168697] Re: linux (Noble): CIFS unmount use-after-free and panic introduced in 6.8.0-136 (CVE-2026-72315)

** Attachment added: "01-prod-6.8.0-137-crash-panic-context.txt" https://bugs.launchpad.net/ubuntu/+source/linux/+bug/2168697/+attachment/6003227/+files/01-prod-6.8.0-137-crash-panic-context.txt -- You received this bug notification because you are subscribed to linux in Ubuntu. Matching subscriptions: Bgg, Bmail, Nb https://bugs.launchpad.net/bugs/2168697 Title: linux (Noble): CIFS unmount use-after-free and panic introduced in 6.8.0-136 (CVE-2026-72315) Status in linux package in Ubuntu: New Bug description: SRU Justification: [ Impact ] Noble 6.8.0-136 backported 340cea84f691 ("cifs: open files should not hold ref on superblock", v7.0) via LP: #2154496. Since then an open cifs file pins only its dentry, so umount(2) can complete while a read-ahead (cifs_readdata on cifsiod_wq), an uncached read/write (cifs_aio_ctx) or a writeback (cifs_writedata) still owns a cifsFileInfo. generic_shutdown_super() finds the inode busy, poisons i_sb with VFS_PTR_POISON, and the later _cifsFileInfo_put() from cifs_readahead_complete() faults on 0xdead0000000000f5 + 0x390. With panic_on_oops=1 the host panics; with panic_on_oops=0 every later umount of a cifs filesystem hangs forever in cifs_kill_sb(). Workloads that mount and unmount SMB shares while a reader is killed (containers, per-job mounts) can hit it. 6.8.0-139 (LP: #2160250) added c68337442f03 ("cifs: Fix busy dentry used after unmounting"), which flushes deferredclose_wq only and covers the deferred-close variant (1 of our 9 production panics). The read-ahead variant (8 of 9) is fixed upstream by 75f5c412fa86 ("smb: client: fix busy dentry warning on unmount after DIO", v7.2, CVE-2026-72315), which is in no Noble 6.8 kernel up to 6.8.0-146 and does not apply as-is because the 6.8 cifs read/write path predates the netfs conversion. Observed: 6.8.0-137 (9 panics / 8 hosts / 30 h on ~850 hosts; lab reproducer panics in 5-90 s) and 6.8.0-146 (lab, ~10 s). Not affected: 6.8.0-111 (same workload, ~3,800 hosts, 0 in 17 days). [ Fix ] Backport of 75f5c412fa86 to the pre-netfs 6.8 code: a per-superblock counter (cifs_sb->outstanding_rreq, as upstream) is taken where a cifs_readdata / cifs_writedata / cifs_aio_ctx acquires its cifsFileInfo reference (including the two writeback sites that transfer an already-held reference) and released after the put in the three release functions. cifs_kill_sb() waits for the counter to reach zero, then flushes serverclose_wq and fileinfo_put_wq before kill_anon_super(), exactly as upstream. A flush-only alternative (flush cifsiod_wq, serverclose_wq, fileinfo_put_wq) was built and tested and still panics: the read request is still on the socket when umount runs, so there is nothing queued to flush. [ Test Plan ] Mount an SMB3 share, start a sequential read of a 2-3 MB file (read-ahead queued), SIGKILL the reader after 1-90 ms, open/close another file, umount immediately; repeat in 4-8 parallel workers on separate mount points (script attached). Stock 6.8.0-137 panics within ~90 s at 8 workers; stock 6.8.0-146 within ~10 s. With the patch on 6.8.0-146.146: ~76,000 cycles against a Dell PowerScale (Isilon) share (krb5, ro) and a Samba share (ro and rw, buffered and O_DIRECT writers, 40-150 ms added server delay) with 0 "Dentry still in use" warnings, 0 faults, 0 hung umounts. We can test a -proposed kernel within minutes. [ Where problems could occur ] The change is confined to fs/smb/client. The counter must balance at every cifsFileInfo acquisition and release of cifs_readdata, cifs_writedata and cifs_aio_ctx; an unbalanced path would make umount(2) wait forever in cifs_kill_sb() (an earlier revision of this port missed the two writeback transfer sites; code review caught it before any write test, which is why they are counted explicitly and the write path was tested separately). The wait runs only at unmount, after the VFS has detached the superblock, so no new I/O can start on it; steady-state I/O paths gain one atomic increment and decrement per request. [ Other Info ] Related but separate: 5520e89a5a4f ("smb: client: fix cifsFileInfo reference leak in deferred close") fixes a refcount leak with a different Fixes: tag; it is not part of this bug. == Evidence (details) == Release: Ubuntu 24.04 LTS (Noble) Package: linux, tested at 6.8.0-137.137 and 6.8.0-146.146 Expected: umount(2) returns and the host continues running. Actual: _cifsFileInfo_put() dereferences an inode after superblock teardown and faults. The host panics with panic_on_oops=1, or later CIFS unmounts hang with panic_on_oops=0. Affected kernels: * Tested: 6.8.0-137.137. We saw 9 production panics on 8 hosts in about   30 hours across about 850 nodes. The lab reproducer panics in 5–90 seconds. * Tested: 6.8.0-146.146 (noble-proposed). The lab reproducer panics in about   10 seconds. * Code-inferred: 6.8.0-136.136, which introduced 340cea84f691c, and   6.8.0-138.138, which predates c68337442f03. * Partial fix from 6.8.0-139.139: c68337442f03 flushes deferredclose_wq only. * Not affected: 6.8.0-111.111. The same workload ran on about 3,800 nodes   for 17 days without an occurrence. This kernel predates 340cea84f691c. == Summary == Noble 6.8.0-136 introduced upstream 340cea84f691c ("cifs: open files should not hold ref on superblock", mainline v7.0) via the upstream-stable patchset tracked by LP: #2154496. After this change, a cifs open file holds only a dentry reference. umount(2) can complete while asynchronous work still owns a cifsFileInfo. When that work later calls _cifsFileInfo_put(), the superblock is gone and the kernel faults on the VFS_PTR_POISON value written into the surviving inode. We observed these paths: * (a) deferredclose: smb2_deferred_work_close -> _cifsFileInfo_put.   Fixed by c68337442f03 in 6.8.0-139 and later. * (b) cifsiod: cifs_readahead_complete -> _cifsFileInfo_put.   Not fixed in any Noble 6.8 kernel through 6.8.0-146. * (c) cifsoplockd: cifs_oplock_break -> _cifsFileInfo_put.   This secondary path appeared only after path (b) had already oopsed with   panic_on_oops=0. We have not demonstrated it as an independent race. In production on 6.8.0-137, path (b) caused 8 panics and path (a) caused 1. On 6.8.0-146 the reproducer triggers path (b), followed by path (c) when panic_on_oops=0. The proposed fix eliminated this complete reproduced sequence. We do not claim that it fixes a separate oplock race. == Impact == With panic_on_oops=1, the whole host panics. With panic_on_oops=0, the oopsed kworkers do not complete and later CIFS unmounts hang in D state at:   __flush_workqueue <- cifs_kill_sb Workloads that mount and unmount SMB shares for each job, such as container workloads, exercise this path continuously. == Kernel log, variant (b) — 6.8.0-137-generic #137-Ubuntu, production == [24042.343670] BUG: Dentry 000000002c909471{i=c34b9,n=<file>} still in use (1) [unmount of cifs cifs] [24042.343678] WARNING: CPU: 28 PID: 1352709 at fs/dcache.c:1528 umount_check+0x64/0x90 [24042.343780] CPU: 28 PID: 1352709 Comm: umount Kdump: loaded Tainted: P OE 6.8.0-137-generic #137-Ubuntu [24042.343783] RIP: 0010:umount_check+0x64/0x90 [24042.343802] d_walk+0xc0/0x2a0 [24042.343810] generic_shutdown_super+0x21/0x180 [24042.343815] cifs_kill_sb+0x5b/0x70 [cifs] [24042.343853] cleanup_mnt+0xc3/0x170 [24042.343938] WARNING: CPU: 28 PID: 1352709 at fs/super.c:649 generic_shutdown_super+0x120/0x180                VFS: Busy inodes after unmount of cifs (cifs) [24043.843507] general protection fault, probably for non-canonical address 0xdead000000000485: 0000 [#1] PREEMPT SMP NOPTI [24043.854484] CPU: 4 PID: 1352168 Comm: kworker/4:1 Kdump: loaded Tainted: P W OE 6.8.0-137-generic #137-Ubuntu [24043.875232] Workqueue: cifsiod cifs_readahead_complete [cifs] [24043.881106] RIP: 0010:_cifsFileInfo_put+0x77/0x4a0 [cifs] [24043.910734] RAX: dead0000000000f5 RBX: ffff8e6ee73a1ea8 RCX: 000000000000000a [24043.983676] cifs_readahead_complete+0x23e/0x2f0 [cifs] [24043.988976] process_one_work+0x181/0x3a0 [24043.993014] worker_thread+0x18b/0x330 [24044.001087] kthread+0xef/0x120 [24044.245052] Kernel panic - not syncing: Fatal exception == Kernel log, variant (a) — 6.8.0-137, production == [17180.976882] BUG: Dentry 00000000e23b32d6{i=34fc,n=<file>} still in use (1) [unmount of cifs cifs] [17180.977008] RIP: 0010:umount_check+0x64/0x90 [17180.977052] cifs_kill_sb+0x5b/0x70 [cifs] [17180.977268] VFS: Busy inodes after unmount of cifs (cifs) [17181.900781] Workqueue: deferredclose smb2_deferred_work_close [cifs] [17181.907243] RIP: 0010:_raw_spin_lock+0x13/0x60 [17182.014078] cifsFileInfo_put_final+0xed/0x120 [cifs] [17182.019221] _cifsFileInfo_put+0x350/0x4a0 [cifs] [17182.028127] smb2_deferred_work_close+0x5f/0x70 [cifs]                Kernel panic - not syncing: Fatal exception == Kernel log, variants (b) and (c) == Kernel: 6.8.0-146-generic #146-Ubuntu, lab, panic_on_oops=0 [ 142.574284] general protection fault, probably for non-canonical address 0xdead000000000485: 0000 [#1] PREEMPT SMP NOPTI [ 142.605742] Workqueue: cifsiod cifs_readahead_complete [cifs] [ 142.611633] RIP: 0010:_cifsFileInfo_put+0x77/0x4a0 [cifs] [ 142.857981] general protection fault, probably for non-canonical address 0xdead000000000485: 0000 [#2] PREEMPT SMP NOPTI [ 142.868925] Workqueue: cifsoplockd cifs_oplock_break [cifs] [ 142.868997] RIP: 0010:cifs_oplock_break+0x43/0x620 [cifs] [ 142.888932] RIP: 0010:_cifsFileInfo_put+0x77/0x4a0 [cifs] (preceded by "BUG: Dentry ... still in use (1) [unmount of cifs cifs]" from umount_check) Afterwards on 6.8.0-146: 8 umount processes in D state, all at   __flush_workqueue+0x14a/0x3e0   <- cifs_kill_sb+0x3c/0x70 [cifs]   <- deactivate_locked_super   <- cleanup_mnt == vmcore analysis (6.8.0-146.146, variant b) == Analysis used crash with linux-image-unsigned-6.8.0-146-generic-dbgsym. The faulting instruction at _cifsFileInfo_put+0x77 is the inlined CIFS_SB(inode->i_sb), which reads sb->s_fs_info at offset 0x390. The inode is d_inode(cifs_file->dentry). Objects in the dump: * inode ffff8bb592233680:   i_ino=0xec6, matching the "i=ec6" umount_check line; i_nlink=1;   i_count=1; i_state=0; still on sb->s_inodes; and   i_op = i_sb = i_mapping = 0xdead0000000000f5 (VFS_PTR_POISON). * dentry ffff8bb5861c7380:   "<file>"; d_lockref.count=1, held by the cifsFileInfo. * superblock ffff8ab5ae3e9800:   type "cifs"; s_count=0; s_active=0; s_root=NULL. * cifsFileInfo ffff8bb551338a00:   allocated from kmalloc-512. * cifs_tcon ffff8ab51c791800:   allocated. generic_shutdown_super() writes this VFS_PTR_POISON value when CHECK_DATA_CORRUPTION(!list_empty(&sb->s_inodes), "VFS: Busy inodes after unmount") fires at fs/super.c:649-663. The read-ahead cifsFileInfo kept the dentry and inode alive across unmount. The superblock was torn down, and the completion work then dereferenced inode->i_sb. This matches the mechanism addressed by 75f5c412fa86: wait for in-flight requests and drain final-put work before kill_anon_super(). The deferredclose_wq flush from c68337442f03 does not cover cifsiod or cifsoplockd work. The vmcore and vmlinux are available on request. == Reproducer (lab, both 6.8.0-137 and 6.8.0-146) == Server: Dell PowerScale (Isilon) SMB3 share, mounted read-only with   -o vers=3.0,sec=krb5,dir_mode=0755,file_mode=0755,noperm,      noserverino,nosharesock,cruid=0,nobrl,ro mount.cifs reports:   cache=strict,soft,nounix,mapposix,rsize=1048576,wsize=1048576 Loop, N parallel workers, each on its own mount point: 1. Mount the share. 2. Start a sequential read, which queues read-ahead:      dd if=<2–3 MB file on the share> of=/dev/null bs=1M & 3. Sleep for 0.01–0.09 seconds, then kill the dd process while I/O is in    flight. 4. Open and close another file to leave a deferred close pending:      head -c 65536 <another file> >/dev/null 5. Immediately unmount the mount point. 6. Repeat. Results: * 6.8.0-137, 8 workers: panic within about 90 seconds (variant b), with a   kdump fingerprint on the BMC. * 6.8.0-137, 4 workers, panic_on_oops=0: oops (b), then (c), within about   5 seconds. * 6.8.0-146, 4 workers for 45 seconds: 5 "Dentry ... still in use"   warnings and no fault. * 6.8.0-146, 8 workers: oops (b), then (c), within about 10 seconds. The "still in use" warning occurs several times per minute with 4 workers on 6.8.0-146. The fault requires the deferred work to run after the superblock is freed, so it becomes more likely with parallel workers. == Regression boundary (from the Noble changelog) == * linux 6.8.0-136.136, "Noble update: upstream stable patchset 2026-05-28"   (LP: #2154496), added:     340cea84f691c (v7.0)     cifs: open files should not hold ref on superblock * linux 6.8.0-139.139, "Noble update: upstream stable patchset 2026-07-09"   (LP: #2160250), added:     c68337442f03 (v7.1, Cc: stable, Fixes: 340cea84f691c)     cifs: Fix busy dentry used after unmounting   This commit adds flush_workqueue(deferredclose_wq) in cifs_kill_sb(). It   covers variant (a) only. * No Noble 6.8 kernel through 6.8.0-146.146 contains:     75f5c412fa86 (v7.2, Fixes: 340cea84f691c)     smb: client: fix busy dentry warning on unmount after DIO   This commit adds cifs_sb->outstanding_rreq, waits for in-flight requests,   and flushes serverclose_wq and fileinfo_put_wq before kill_anon_super().   This is the mechanism that covers variants (b) and (c). == Request == Track this under CVE-2026-72315, the outstanding-I/O defect fixed by 75f5c412fa86. 1. Apply the attached Noble 6.8 backport of 75f5c412fa86. Noble predates    the cifs netfs conversion, so the backport accounts for the cifsFileInfo    references held by cifs_readdata, cifs_writedata and cifs_aio_ctx instead    of netfs requests. cifs_kill_sb() waits for that per-superblock count to    reach zero, then flushes serverclose_wq and fileinfo_put_wq before    kill_anon_super(). The patch survived about 76,000 tested cycles. The    flush-only alternative still panicked within about 30 seconds with the    same cifsiod/cifs_readahead_complete trace. 2. We can validate a candidate kernel within minutes with the attached    reproducer. 3. Consider noting in the 6.8.0-136, 6.8.0-137 and 6.8.0-138 release notes    that 340cea84f691c shipped without its stable follow-up c68337442f03. Related but separate: 5520e89a5a4f ("smb: client: fix cifsFileInfo reference leak in deferred close", Fixes: c3f207ab29f7) fixes a refcount leak when queue_delayed_work() finds work already pending. It has a different Fixes commit and is not asserted to cause this panic. Please track it separately. == Environment / attachments == Ubuntu 24.04 (Noble), x86_64, HPE ProLiant XL225n Gen10 Plus, in-tree cifs.ko 2.47, and SMB3 to Dell PowerScale. Production mounts and unmounts the share for each cri-o container lifecycle. The lab uses a hand-driven loop. /proc/version_signature reported:   Ubuntu 6.8.0-137.137-generic 6.8.12   Ubuntu 6.8.0-146.146-generic 6.8.12 A 3.4 GB kdump vmcore of the 6.8.0-146.146 variant-(b) panic was captured on 2026-09-27 with makedumpfile -c -d 31. It is available on request with the matching vmlinux. Its dmesg is attached. To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/linux/+bug/2168697/+subscriptions

[Bug 2168698] [NEW] Keeps freezing

Public bug reported: My Ubuntu keeps freezing and I can't find the reason. ProblemType: Bug DistroRelease: Ubuntu 26.04 Package: linux-image-7.0.0-34-generic 7.0.0-34.34 ProcVersionSignature: Ubuntu 7.0.0-34.34-generic 7.0.14 Uname: Linux 7.0.0-34-generic x86_64 NonfreeKernelModules: nvidia_modeset nvidia ApportVersion: 2.34.1-0ubuntu0.1 Architecture: amd64 AudioDevicesInUse: USER PID ACCESS COMMAND /dev/snd/controlC1: ilia 4416 F.... wireplumber /dev/snd/controlC0: ilia 4416 F.... wireplumber /dev/snd/controlC2: ilia 4416 F.... wireplumber /dev/snd/seq: ilia 4397 F.... pipewire CasperMD5CheckResult: pass CurrentDesktop: ubuntu:GNOME Date: Mon Sep 28 01:11:08 2026 InstallationDate: Installed on 2026-08-12 (46 days ago) InstallationMedia: Ubuntu 26.04 "Resolute Raccoon" - Release amd64 (20260423.1) MachineType: ASUS All Series ProcEnviron: LANG=en_US.UTF-8 PATH=(custom, no user) SHELL=/bin/bash TERM=xterm-256color XDG_RUNTIME_DIR=<set> ProcFB: 0 i915drmfb ProcKernelCmdLine: BOOT_IMAGE=/vmlinuz-7.0.0-34-generic root=/dev/mapper/ubuntu--vg-ubuntu--lv ro quiet splash intel_idle.max_cstate=1 crashkernel=2G-4G:320M,4G-32G:512M,32G-64G:1024M,64G-128G:2048M,128G-:4096M SourcePackage: linux UpgradeStatus: No upgrade log present (probably fresh install) dmi.bios.date: 12/08/2014 dmi.bios.release: 4.6 dmi.bios.vendor: American Megatrends Inc. dmi.bios.version: 2202 dmi.board.asset.tag: To be filled by O.E.M. dmi.board.name: B85M-G dmi.board.vendor: ASUSTeK COMPUTER INC. dmi.board.version: Rev X.0x dmi.chassis.asset.tag: Asset-1234567890 dmi.chassis.type: 3 dmi.chassis.vendor: Chassis Manufacture dmi.chassis.version: Chassis Version dmi.modalias: dmi:bvnAmericanMegatrendsInc.:bvr2202:bd12/08/2014:br4.6:svnASUS:pnAllSeries:pvrSystemVersion:rvnASUSTeKCOMPUTERINC.:rnB85M-G:rvrRevX.0x:cvnChassisManufacture:ct3:cvrChassisVersion:skuAll:pfaASUSMB: dmi.product.family: ASUS MB dmi.product.name: All Series dmi.product.sku: All dmi.product.version: System Version dmi.sys.vendor: ASUS ** Affects: linux (Ubuntu) Importance: Undecided Status: New ** Tags: amd64 apport-bug resolute wayland-session -- You received this bug notification because you are subscribed to linux in Ubuntu. Matching subscriptions: Bgg, Bmail, Nb https://bugs.launchpad.net/bugs/2168698 Title: Keeps freezing Status in linux package in Ubuntu: New Bug description: My Ubuntu keeps freezing and I can't find the reason. ProblemType: Bug DistroRelease: Ubuntu 26.04 Package: linux-image-7.0.0-34-generic 7.0.0-34.34 ProcVersionSignature: Ubuntu 7.0.0-34.34-generic 7.0.14 Uname: Linux 7.0.0-34-generic x86_64 NonfreeKernelModules: nvidia_modeset nvidia ApportVersion: 2.34.1-0ubuntu0.1 Architecture: amd64 AudioDevicesInUse: USER PID ACCESS COMMAND /dev/snd/controlC1: ilia 4416 F.... wireplumber /dev/snd/controlC0: ilia 4416 F.... wireplumber /dev/snd/controlC2: ilia 4416 F.... wireplumber /dev/snd/seq: ilia 4397 F.... pipewire CasperMD5CheckResult: pass CurrentDesktop: ubuntu:GNOME Date: Mon Sep 28 01:11:08 2026 InstallationDate: Installed on 2026-08-12 (46 days ago) InstallationMedia: Ubuntu 26.04 "Resolute Raccoon" - Release amd64 (20260423.1) MachineType: ASUS All Series ProcEnviron: LANG=en_US.UTF-8 PATH=(custom, no user) SHELL=/bin/bash TERM=xterm-256color XDG_RUNTIME_DIR=<set> ProcFB: 0 i915drmfb ProcKernelCmdLine: BOOT_IMAGE=/vmlinuz-7.0.0-34-generic root=/dev/mapper/ubuntu--vg-ubuntu--lv ro quiet splash intel_idle.max_cstate=1 crashkernel=2G-4G:320M,4G-32G:512M,32G-64G:1024M,64G-128G:2048M,128G-:4096M SourcePackage: linux UpgradeStatus: No upgrade log present (probably fresh install) dmi.bios.date: 12/08/2014 dmi.bios.release: 4.6 dmi.bios.vendor: American Megatrends Inc. dmi.bios.version: 2202 dmi.board.asset.tag: To be filled by O.E.M. dmi.board.name: B85M-G dmi.board.vendor: ASUSTeK COMPUTER INC. dmi.board.version: Rev X.0x dmi.chassis.asset.tag: Asset-1234567890 dmi.chassis.type: 3 dmi.chassis.vendor: Chassis Manufacture dmi.chassis.version: Chassis Version dmi.modalias: dmi:bvnAmericanMegatrendsInc.:bvr2202:bd12/08/2014:br4.6:svnASUS:pnAllSeries:pvrSystemVersion:rvnASUSTeKCOMPUTERINC.:rnB85M-G:rvrRevX.0x:cvnChassisManufacture:ct3:cvrChassisVersion:skuAll:pfaASUSMB: dmi.product.family: ASUS MB dmi.product.name: All Series dmi.product.sku: All dmi.product.version: System Version dmi.sys.vendor: ASUS To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/linux/+bug/2168698/+subscriptions

[Bug 2168697] [NEW] linux (Noble): CIFS unmount use-after-free and panic introduced in 6.8.0-136 (CVE-2026-72315)

Public bug reported: SRU Justification: [ Impact ] Noble 6.8.0-136 backported 340cea84f691 ("cifs: open files should not hold ref on superblock", v7.0) via LP: #2154496. Since then an open cifs file pins only its dentry, so umount(2) can complete while a read-ahead (cifs_readdata on cifsiod_wq), an uncached read/write (cifs_aio_ctx) or a writeback (cifs_writedata) still owns a cifsFileInfo. generic_shutdown_super() finds the inode busy, poisons i_sb with VFS_PTR_POISON, and the later _cifsFileInfo_put() from cifs_readahead_complete() faults on 0xdead0000000000f5 + 0x390. With panic_on_oops=1 the host panics; with panic_on_oops=0 every later umount of a cifs filesystem hangs forever in cifs_kill_sb(). Workloads that mount and unmount SMB shares while a reader is killed (containers, per-job mounts) can hit it. 6.8.0-139 (LP: #2160250) added c68337442f03 ("cifs: Fix busy dentry used after unmounting"), which flushes deferredclose_wq only and covers the deferred-close variant (1 of our 9 production panics). The read-ahead variant (8 of 9) is fixed upstream by 75f5c412fa86 ("smb: client: fix busy dentry warning on unmount after DIO", v7.2, CVE-2026-72315), which is in no Noble 6.8 kernel up to 6.8.0-146 and does not apply as-is because the 6.8 cifs read/write path predates the netfs conversion. Observed: 6.8.0-137 (9 panics / 8 hosts / 30 h on ~850 hosts; lab reproducer panics in 5-90 s) and 6.8.0-146 (lab, ~10 s). Not affected: 6.8.0-111 (same workload, ~3,800 hosts, 0 in 17 days). [ Fix ] Backport of 75f5c412fa86 to the pre-netfs 6.8 code: a per-superblock counter (cifs_sb->outstanding_rreq, as upstream) is taken where a cifs_readdata / cifs_writedata / cifs_aio_ctx acquires its cifsFileInfo reference (including the two writeback sites that transfer an already-held reference) and released after the put in the three release functions. cifs_kill_sb() waits for the counter to reach zero, then flushes serverclose_wq and fileinfo_put_wq before kill_anon_super(), exactly as upstream. A flush-only alternative (flush cifsiod_wq, serverclose_wq, fileinfo_put_wq) was built and tested and still panics: the read request is still on the socket when umount runs, so there is nothing queued to flush. [ Test Plan ] Mount an SMB3 share, start a sequential read of a 2-3 MB file (read-ahead queued), SIGKILL the reader after 1-90 ms, open/close another file, umount immediately; repeat in 4-8 parallel workers on separate mount points (script attached). Stock 6.8.0-137 panics within ~90 s at 8 workers; stock 6.8.0-146 within ~10 s. With the patch on 6.8.0-146.146: ~76,000 cycles against a Dell PowerScale (Isilon) share (krb5, ro) and a Samba share (ro and rw, buffered and O_DIRECT writers, 40-150 ms added server delay) with 0 "Dentry still in use" warnings, 0 faults, 0 hung umounts. We can test a -proposed kernel within minutes. [ Where problems could occur ] The change is confined to fs/smb/client. The counter must balance at every cifsFileInfo acquisition and release of cifs_readdata, cifs_writedata and cifs_aio_ctx; an unbalanced path would make umount(2) wait forever in cifs_kill_sb() (an earlier revision of this port missed the two writeback transfer sites; code review caught it before any write test, which is why they are counted explicitly and the write path was tested separately). The wait runs only at unmount, after the VFS has detached the superblock, so no new I/O can start on it; steady-state I/O paths gain one atomic increment and decrement per request. [ Other Info ] Related but separate: 5520e89a5a4f ("smb: client: fix cifsFileInfo reference leak in deferred close") fixes a refcount leak with a different Fixes: tag; it is not part of this bug. == Evidence (details) == Release: Ubuntu 24.04 LTS (Noble) Package: linux, tested at 6.8.0-137.137 and 6.8.0-146.146 Expected: umount(2) returns and the host continues running. Actual: _cifsFileInfo_put() dereferences an inode after superblock teardown and faults. The host panics with panic_on_oops=1, or later CIFS unmounts hang with panic_on_oops=0. Affected kernels: * Tested: 6.8.0-137.137. We saw 9 production panics on 8 hosts in about 30 hours across about 850 nodes. The lab reproducer panics in 5–90 seconds. * Tested: 6.8.0-146.146 (noble-proposed). The lab reproducer panics in about 10 seconds. * Code-inferred: 6.8.0-136.136, which introduced 340cea84f691c, and 6.8.0-138.138, which predates c68337442f03. * Partial fix from 6.8.0-139.139: c68337442f03 flushes deferredclose_wq only. * Not affected: 6.8.0-111.111. The same workload ran on about 3,800 nodes for 17 days without an occurrence. This kernel predates 340cea84f691c. == Summary == Noble 6.8.0-136 introduced upstream 340cea84f691c ("cifs: open files should not hold ref on superblock", mainline v7.0) via the upstream-stable patchset tracked by LP: #2154496. After this change, a cifs open file holds only a dentry reference. umount(2) can complete while asynchronous work still owns a cifsFileInfo. When that work later calls _cifsFileInfo_put(), the superblock is gone and the kernel faults on the VFS_PTR_POISON value written into the surviving inode. We observed these paths: * (a) deferredclose: smb2_deferred_work_close -> _cifsFileInfo_put. Fixed by c68337442f03 in 6.8.0-139 and later. * (b) cifsiod: cifs_readahead_complete -> _cifsFileInfo_put. Not fixed in any Noble 6.8 kernel through 6.8.0-146. * (c) cifsoplockd: cifs_oplock_break -> _cifsFileInfo_put. This secondary path appeared only after path (b) had already oopsed with panic_on_oops=0. We have not demonstrated it as an independent race. In production on 6.8.0-137, path (b) caused 8 panics and path (a) caused 1. On 6.8.0-146 the reproducer triggers path (b), followed by path (c) when panic_on_oops=0. The proposed fix eliminated this complete reproduced sequence. We do not claim that it fixes a separate oplock race. == Impact == With panic_on_oops=1, the whole host panics. With panic_on_oops=0, the oopsed kworkers do not complete and later CIFS unmounts hang in D state at: __flush_workqueue <- cifs_kill_sb Workloads that mount and unmount SMB shares for each job, such as container workloads, exercise this path continuously. == Kernel log, variant (b) — 6.8.0-137-generic #137-Ubuntu, production == [24042.343670] BUG: Dentry 000000002c909471{i=c34b9,n=<file>} still in use (1) [unmount of cifs cifs] [24042.343678] WARNING: CPU: 28 PID: 1352709 at fs/dcache.c:1528 umount_check+0x64/0x90 [24042.343780] CPU: 28 PID: 1352709 Comm: umount Kdump: loaded Tainted: P OE 6.8.0-137-generic #137-Ubuntu [24042.343783] RIP: 0010:umount_check+0x64/0x90 [24042.343802] d_walk+0xc0/0x2a0 [24042.343810] generic_shutdown_super+0x21/0x180 [24042.343815] cifs_kill_sb+0x5b/0x70 [cifs] [24042.343853] cleanup_mnt+0xc3/0x170 [24042.343938] WARNING: CPU: 28 PID: 1352709 at fs/super.c:649 generic_shutdown_super+0x120/0x180 VFS: Busy inodes after unmount of cifs (cifs) [24043.843507] general protection fault, probably for non-canonical address 0xdead000000000485: 0000 [#1] PREEMPT SMP NOPTI [24043.854484] CPU: 4 PID: 1352168 Comm: kworker/4:1 Kdump: loaded Tainted: P W OE 6.8.0-137-generic #137-Ubuntu [24043.875232] Workqueue: cifsiod cifs_readahead_complete [cifs] [24043.881106] RIP: 0010:_cifsFileInfo_put+0x77/0x4a0 [cifs] [24043.910734] RAX: dead0000000000f5 RBX: ffff8e6ee73a1ea8 RCX: 000000000000000a [24043.983676] cifs_readahead_complete+0x23e/0x2f0 [cifs] [24043.988976] process_one_work+0x181/0x3a0 [24043.993014] worker_thread+0x18b/0x330 [24044.001087] kthread+0xef/0x120 [24044.245052] Kernel panic - not syncing: Fatal exception == Kernel log, variant (a) — 6.8.0-137, production == [17180.976882] BUG: Dentry 00000000e23b32d6{i=34fc,n=<file>} still in use (1) [unmount of cifs cifs] [17180.977008] RIP: 0010:umount_check+0x64/0x90 [17180.977052] cifs_kill_sb+0x5b/0x70 [cifs] [17180.977268] VFS: Busy inodes after unmount of cifs (cifs) [17181.900781] Workqueue: deferredclose smb2_deferred_work_close [cifs] [17181.907243] RIP: 0010:_raw_spin_lock+0x13/0x60 [17182.014078] cifsFileInfo_put_final+0xed/0x120 [cifs] [17182.019221] _cifsFileInfo_put+0x350/0x4a0 [cifs] [17182.028127] smb2_deferred_work_close+0x5f/0x70 [cifs] Kernel panic - not syncing: Fatal exception == Kernel log, variants (b) and (c) == Kernel: 6.8.0-146-generic #146-Ubuntu, lab, panic_on_oops=0 [ 142.574284] general protection fault, probably for non-canonical address 0xdead000000000485: 0000 [#1] PREEMPT SMP NOPTI [ 142.605742] Workqueue: cifsiod cifs_readahead_complete [cifs] [ 142.611633] RIP: 0010:_cifsFileInfo_put+0x77/0x4a0 [cifs] [ 142.857981] general protection fault, probably for non-canonical address 0xdead000000000485: 0000 [#2] PREEMPT SMP NOPTI [ 142.868925] Workqueue: cifsoplockd cifs_oplock_break [cifs] [ 142.868997] RIP: 0010:cifs_oplock_break+0x43/0x620 [cifs] [ 142.888932] RIP: 0010:_cifsFileInfo_put+0x77/0x4a0 [cifs] (preceded by "BUG: Dentry ... still in use (1) [unmount of cifs cifs]" from umount_check) Afterwards on 6.8.0-146: 8 umount processes in D state, all at __flush_workqueue+0x14a/0x3e0 <- cifs_kill_sb+0x3c/0x70 [cifs] <- deactivate_locked_super <- cleanup_mnt == vmcore analysis (6.8.0-146.146, variant b) == Analysis used crash with linux-image-unsigned-6.8.0-146-generic-dbgsym. The faulting instruction at _cifsFileInfo_put+0x77 is the inlined CIFS_SB(inode->i_sb), which reads sb->s_fs_info at offset 0x390. The inode is d_inode(cifs_file->dentry). Objects in the dump: * inode ffff8bb592233680: i_ino=0xec6, matching the "i=ec6" umount_check line; i_nlink=1; i_count=1; i_state=0; still on sb->s_inodes; and i_op = i_sb = i_mapping = 0xdead0000000000f5 (VFS_PTR_POISON). * dentry ffff8bb5861c7380: "<file>"; d_lockref.count=1, held by the cifsFileInfo. * superblock ffff8ab5ae3e9800: type "cifs"; s_count=0; s_active=0; s_root=NULL. * cifsFileInfo ffff8bb551338a00: allocated from kmalloc-512. * cifs_tcon ffff8ab51c791800: allocated. generic_shutdown_super() writes this VFS_PTR_POISON value when CHECK_DATA_CORRUPTION(!list_empty(&sb->s_inodes), "VFS: Busy inodes after unmount") fires at fs/super.c:649-663. The read-ahead cifsFileInfo kept the dentry and inode alive across unmount. The superblock was torn down, and the completion work then dereferenced inode->i_sb. This matches the mechanism addressed by 75f5c412fa86: wait for in-flight requests and drain final-put work before kill_anon_super(). The deferredclose_wq flush from c68337442f03 does not cover cifsiod or cifsoplockd work. The vmcore and vmlinux are available on request. == Reproducer (lab, both 6.8.0-137 and 6.8.0-146) == Server: Dell PowerScale (Isilon) SMB3 share, mounted read-only with -o vers=3.0,sec=krb5,dir_mode=0755,file_mode=0755,noperm, noserverino,nosharesock,cruid=0,nobrl,ro mount.cifs reports: cache=strict,soft,nounix,mapposix,rsize=1048576,wsize=1048576 Loop, N parallel workers, each on its own mount point: 1. Mount the share. 2. Start a sequential read, which queues read-ahead: dd if=<2–3 MB file on the share> of=/dev/null bs=1M & 3. Sleep for 0.01–0.09 seconds, then kill the dd process while I/O is in flight. 4. Open and close another file to leave a deferred close pending: head -c 65536 <another file> >/dev/null 5. Immediately unmount the mount point. 6. Repeat. Results: * 6.8.0-137, 8 workers: panic within about 90 seconds (variant b), with a kdump fingerprint on the BMC. * 6.8.0-137, 4 workers, panic_on_oops=0: oops (b), then (c), within about 5 seconds. * 6.8.0-146, 4 workers for 45 seconds: 5 "Dentry ... still in use" warnings and no fault. * 6.8.0-146, 8 workers: oops (b), then (c), within about 10 seconds. The "still in use" warning occurs several times per minute with 4 workers on 6.8.0-146. The fault requires the deferred work to run after the superblock is freed, so it becomes more likely with parallel workers. == Regression boundary (from the Noble changelog) == * linux 6.8.0-136.136, "Noble update: upstream stable patchset 2026-05-28" (LP: #2154496), added: 340cea84f691c (v7.0) cifs: open files should not hold ref on superblock * linux 6.8.0-139.139, "Noble update: upstream stable patchset 2026-07-09" (LP: #2160250), added: c68337442f03 (v7.1, Cc: stable, Fixes: 340cea84f691c) cifs: Fix busy dentry used after unmounting This commit adds flush_workqueue(deferredclose_wq) in cifs_kill_sb(). It covers variant (a) only. * No Noble 6.8 kernel through 6.8.0-146.146 contains: 75f5c412fa86 (v7.2, Fixes: 340cea84f691c) smb: client: fix busy dentry warning on unmount after DIO This commit adds cifs_sb->outstanding_rreq, waits for in-flight requests, and flushes serverclose_wq and fileinfo_put_wq before kill_anon_super(). This is the mechanism that covers variants (b) and (c). == Request == Track this under CVE-2026-72315, the outstanding-I/O defect fixed by 75f5c412fa86. 1. Apply the attached Noble 6.8 backport of 75f5c412fa86. Noble predates the cifs netfs conversion, so the backport accounts for the cifsFileInfo references held by cifs_readdata, cifs_writedata and cifs_aio_ctx instead of netfs requests. cifs_kill_sb() waits for that per-superblock count to reach zero, then flushes serverclose_wq and fileinfo_put_wq before kill_anon_super(). The patch survived about 76,000 tested cycles. The flush-only alternative still panicked within about 30 seconds with the same cifsiod/cifs_readahead_complete trace. 2. We can validate a candidate kernel within minutes with the attached reproducer. 3. Consider noting in the 6.8.0-136, 6.8.0-137 and 6.8.0-138 release notes that 340cea84f691c shipped without its stable follow-up c68337442f03. Related but separate: 5520e89a5a4f ("smb: client: fix cifsFileInfo reference leak in deferred close", Fixes: c3f207ab29f7) fixes a refcount leak when queue_delayed_work() finds work already pending. It has a different Fixes commit and is not asserted to cause this panic. Please track it separately. == Environment / attachments == Ubuntu 24.04 (Noble), x86_64, HPE ProLiant XL225n Gen10 Plus, in-tree cifs.ko 2.47, and SMB3 to Dell PowerScale. Production mounts and unmounts the share for each cri-o container lifecycle. The lab uses a hand-driven loop. Attached evidence: * Production panic context and kworker trace. * Firmware pstore record from a lab 6.8.0-137 panic. * Live and vmcore dmesg from stock 6.8.0-146. * Vmcore analysis. * Reproducer. * Version, PCI, release and package metadata. * Tested SRU patch. /proc/version_signature reported: Ubuntu 6.8.0-137.137-generic 6.8.12 Ubuntu 6.8.0-146.146-generic 6.8.12 A 3.4 GB kdump vmcore of the 6.8.0-146.146 variant-(b) panic was captured on 2026-09-27 with makedumpfile -c -d 31. It is available on request with the matching vmlinux. Its dmesg and object analysis are attached. ** Affects: linux (Ubuntu) Importance: Undecided Status: New ** Attachment added: "affected version" https://bugs.launchpad.net/bugs/2168697/+attachment/6003206/+files/version.log -- You received this bug notification because you are subscribed to linux in Ubuntu. Matching subscriptions: Bgg, Bmail, Nb https://bugs.launchpad.net/bugs/2168697 Title: linux (Noble): CIFS unmount use-after-free and panic introduced in 6.8.0-136 (CVE-2026-72315) Status in linux package in Ubuntu: New Bug description: SRU Justification: [ Impact ] Noble 6.8.0-136 backported 340cea84f691 ("cifs: open files should not hold ref on superblock", v7.0) via LP: #2154496. Since then an open cifs file pins only its dentry, so umount(2) can complete while a read-ahead (cifs_readdata on cifsiod_wq), an uncached read/write (cifs_aio_ctx) or a writeback (cifs_writedata) still owns a cifsFileInfo. generic_shutdown_super() finds the inode busy, poisons i_sb with VFS_PTR_POISON, and the later _cifsFileInfo_put() from cifs_readahead_complete() faults on 0xdead0000000000f5 + 0x390. With panic_on_oops=1 the host panics; with panic_on_oops=0 every later umount of a cifs filesystem hangs forever in cifs_kill_sb(). Workloads that mount and unmount SMB shares while a reader is killed (containers, per-job mounts) can hit it. 6.8.0-139 (LP: #2160250) added c68337442f03 ("cifs: Fix busy dentry used after unmounting"), which flushes deferredclose_wq only and covers the deferred-close variant (1 of our 9 production panics). The read-ahead variant (8 of 9) is fixed upstream by 75f5c412fa86 ("smb: client: fix busy dentry warning on unmount after DIO", v7.2, CVE-2026-72315), which is in no Noble 6.8 kernel up to 6.8.0-146 and does not apply as-is because the 6.8 cifs read/write path predates the netfs conversion. Observed: 6.8.0-137 (9 panics / 8 hosts / 30 h on ~850 hosts; lab reproducer panics in 5-90 s) and 6.8.0-146 (lab, ~10 s). Not affected: 6.8.0-111 (same workload, ~3,800 hosts, 0 in 17 days). [ Fix ] Backport of 75f5c412fa86 to the pre-netfs 6.8 code: a per-superblock counter (cifs_sb->outstanding_rreq, as upstream) is taken where a cifs_readdata / cifs_writedata / cifs_aio_ctx acquires its cifsFileInfo reference (including the two writeback sites that transfer an already-held reference) and released after the put in the three release functions. cifs_kill_sb() waits for the counter to reach zero, then flushes serverclose_wq and fileinfo_put_wq before kill_anon_super(), exactly as upstream. A flush-only alternative (flush cifsiod_wq, serverclose_wq, fileinfo_put_wq) was built and tested and still panics: the read request is still on the socket when umount runs, so there is nothing queued to flush. [ Test Plan ] Mount an SMB3 share, start a sequential read of a 2-3 MB file (read-ahead queued), SIGKILL the reader after 1-90 ms, open/close another file, umount immediately; repeat in 4-8 parallel workers on separate mount points (script attached). Stock 6.8.0-137 panics within ~90 s at 8 workers; stock 6.8.0-146 within ~10 s. With the patch on 6.8.0-146.146: ~76,000 cycles against a Dell PowerScale (Isilon) share (krb5, ro) and a Samba share (ro and rw, buffered and O_DIRECT writers, 40-150 ms added server delay) with 0 "Dentry still in use" warnings, 0 faults, 0 hung umounts. We can test a -proposed kernel within minutes. [ Where problems could occur ] The change is confined to fs/smb/client. The counter must balance at every cifsFileInfo acquisition and release of cifs_readdata, cifs_writedata and cifs_aio_ctx; an unbalanced path would make umount(2) wait forever in cifs_kill_sb() (an earlier revision of this port missed the two writeback transfer sites; code review caught it before any write test, which is why they are counted explicitly and the write path was tested separately). The wait runs only at unmount, after the VFS has detached the superblock, so no new I/O can start on it; steady-state I/O paths gain one atomic increment and decrement per request. [ Other Info ] Related but separate: 5520e89a5a4f ("smb: client: fix cifsFileInfo reference leak in deferred close") fixes a refcount leak with a different Fixes: tag; it is not part of this bug. == Evidence (details) == Release: Ubuntu 24.04 LTS (Noble) Package: linux, tested at 6.8.0-137.137 and 6.8.0-146.146 Expected: umount(2) returns and the host continues running. Actual: _cifsFileInfo_put() dereferences an inode after superblock teardown and faults. The host panics with panic_on_oops=1, or later CIFS unmounts hang with panic_on_oops=0. Affected kernels: * Tested: 6.8.0-137.137. We saw 9 production panics on 8 hosts in about 30 hours across about 850 nodes. The lab reproducer panics in 5–90 seconds. * Tested: 6.8.0-146.146 (noble-proposed). The lab reproducer panics in about 10 seconds. * Code-inferred: 6.8.0-136.136, which introduced 340cea84f691c, and 6.8.0-138.138, which predates c68337442f03. * Partial fix from 6.8.0-139.139: c68337442f03 flushes deferredclose_wq only. * Not affected: 6.8.0-111.111. The same workload ran on about 3,800 nodes for 17 days without an occurrence. This kernel predates 340cea84f691c. == Summary == Noble 6.8.0-136 introduced upstream 340cea84f691c ("cifs: open files should not hold ref on superblock", mainline v7.0) via the upstream-stable patchset tracked by LP: #2154496. After this change, a cifs open file holds only a dentry reference. umount(2) can complete while asynchronous work still owns a cifsFileInfo. When that work later calls _cifsFileInfo_put(), the superblock is gone and the kernel faults on the VFS_PTR_POISON value written into the surviving inode. We observed these paths: * (a) deferredclose: smb2_deferred_work_close -> _cifsFileInfo_put. Fixed by c68337442f03 in 6.8.0-139 and later. * (b) cifsiod: cifs_readahead_complete -> _cifsFileInfo_put. Not fixed in any Noble 6.8 kernel through 6.8.0-146. * (c) cifsoplockd: cifs_oplock_break -> _cifsFileInfo_put. This secondary path appeared only after path (b) had already oopsed with panic_on_oops=0. We have not demonstrated it as an independent race. In production on 6.8.0-137, path (b) caused 8 panics and path (a) caused 1. On 6.8.0-146 the reproducer triggers path (b), followed by path (c) when panic_on_oops=0. The proposed fix eliminated this complete reproduced sequence. We do not claim that it fixes a separate oplock race. == Impact == With panic_on_oops=1, the whole host panics. With panic_on_oops=0, the oopsed kworkers do not complete and later CIFS unmounts hang in D state at: __flush_workqueue <- cifs_kill_sb Workloads that mount and unmount SMB shares for each job, such as container workloads, exercise this path continuously. == Kernel log, variant (b) — 6.8.0-137-generic #137-Ubuntu, production == [24042.343670] BUG: Dentry 000000002c909471{i=c34b9,n=<file>} still in use (1) [unmount of cifs cifs] [24042.343678] WARNING: CPU: 28 PID: 1352709 at fs/dcache.c:1528 umount_check+0x64/0x90 [24042.343780] CPU: 28 PID: 1352709 Comm: umount Kdump: loaded Tainted: P OE 6.8.0-137-generic #137-Ubuntu [24042.343783] RIP: 0010:umount_check+0x64/0x90 [24042.343802] d_walk+0xc0/0x2a0 [24042.343810] generic_shutdown_super+0x21/0x180 [24042.343815] cifs_kill_sb+0x5b/0x70 [cifs] [24042.343853] cleanup_mnt+0xc3/0x170 [24042.343938] WARNING: CPU: 28 PID: 1352709 at fs/super.c:649 generic_shutdown_super+0x120/0x180 VFS: Busy inodes after unmount of cifs (cifs) [24043.843507] general protection fault, probably for non-canonical address 0xdead000000000485: 0000 [#1] PREEMPT SMP NOPTI [24043.854484] CPU: 4 PID: 1352168 Comm: kworker/4:1 Kdump: loaded Tainted: P W OE 6.8.0-137-generic #137-Ubuntu [24043.875232] Workqueue: cifsiod cifs_readahead_complete [cifs] [24043.881106] RIP: 0010:_cifsFileInfo_put+0x77/0x4a0 [cifs] [24043.910734] RAX: dead0000000000f5 RBX: ffff8e6ee73a1ea8 RCX: 000000000000000a [24043.983676] cifs_readahead_complete+0x23e/0x2f0 [cifs] [24043.988976] process_one_work+0x181/0x3a0 [24043.993014] worker_thread+0x18b/0x330 [24044.001087] kthread+0xef/0x120 [24044.245052] Kernel panic - not syncing: Fatal exception == Kernel log, variant (a) — 6.8.0-137, production == [17180.976882] BUG: Dentry 00000000e23b32d6{i=34fc,n=<file>} still in use (1) [unmount of cifs cifs] [17180.977008] RIP: 0010:umount_check+0x64/0x90 [17180.977052] cifs_kill_sb+0x5b/0x70 [cifs] [17180.977268] VFS: Busy inodes after unmount of cifs (cifs) [17181.900781] Workqueue: deferredclose smb2_deferred_work_close [cifs] [17181.907243] RIP: 0010:_raw_spin_lock+0x13/0x60 [17182.014078] cifsFileInfo_put_final+0xed/0x120 [cifs] [17182.019221] _cifsFileInfo_put+0x350/0x4a0 [cifs] [17182.028127] smb2_deferred_work_close+0x5f/0x70 [cifs] Kernel panic - not syncing: Fatal exception == Kernel log, variants (b) and (c) == Kernel: 6.8.0-146-generic #146-Ubuntu, lab, panic_on_oops=0 [ 142.574284] general protection fault, probably for non-canonical address 0xdead000000000485: 0000 [#1] PREEMPT SMP NOPTI [ 142.605742] Workqueue: cifsiod cifs_readahead_complete [cifs] [ 142.611633] RIP: 0010:_cifsFileInfo_put+0x77/0x4a0 [cifs] [ 142.857981] general protection fault, probably for non-canonical address 0xdead000000000485: 0000 [#2] PREEMPT SMP NOPTI [ 142.868925] Workqueue: cifsoplockd cifs_oplock_break [cifs] [ 142.868997] RIP: 0010:cifs_oplock_break+0x43/0x620 [cifs] [ 142.888932] RIP: 0010:_cifsFileInfo_put+0x77/0x4a0 [cifs] (preceded by "BUG: Dentry ... still in use (1) [unmount of cifs cifs]" from umount_check) Afterwards on 6.8.0-146: 8 umount processes in D state, all at __flush_workqueue+0x14a/0x3e0 <- cifs_kill_sb+0x3c/0x70 [cifs] <- deactivate_locked_super <- cleanup_mnt == vmcore analysis (6.8.0-146.146, variant b) == Analysis used crash with linux-image-unsigned-6.8.0-146-generic-dbgsym. The faulting instruction at _cifsFileInfo_put+0x77 is the inlined CIFS_SB(inode->i_sb), which reads sb->s_fs_info at offset 0x390. The inode is d_inode(cifs_file->dentry). Objects in the dump: * inode ffff8bb592233680: i_ino=0xec6, matching the "i=ec6" umount_check line; i_nlink=1; i_count=1; i_state=0; still on sb->s_inodes; and i_op = i_sb = i_mapping = 0xdead0000000000f5 (VFS_PTR_POISON). * dentry ffff8bb5861c7380: "<file>"; d_lockref.count=1, held by the cifsFileInfo. * superblock ffff8ab5ae3e9800: type "cifs"; s_count=0; s_active=0; s_root=NULL. * cifsFileInfo ffff8bb551338a00: allocated from kmalloc-512. * cifs_tcon ffff8ab51c791800: allocated. generic_shutdown_super() writes this VFS_PTR_POISON value when CHECK_DATA_CORRUPTION(!list_empty(&sb->s_inodes), "VFS: Busy inodes after unmount") fires at fs/super.c:649-663. The read-ahead cifsFileInfo kept the dentry and inode alive across unmount. The superblock was torn down, and the completion work then dereferenced inode->i_sb. This matches the mechanism addressed by 75f5c412fa86: wait for in-flight requests and drain final-put work before kill_anon_super(). The deferredclose_wq flush from c68337442f03 does not cover cifsiod or cifsoplockd work. The vmcore and vmlinux are available on request. == Reproducer (lab, both 6.8.0-137 and 6.8.0-146) == Server: Dell PowerScale (Isilon) SMB3 share, mounted read-only with -o vers=3.0,sec=krb5,dir_mode=0755,file_mode=0755,noperm, noserverino,nosharesock,cruid=0,nobrl,ro mount.cifs reports: cache=strict,soft,nounix,mapposix,rsize=1048576,wsize=1048576 Loop, N parallel workers, each on its own mount point: 1. Mount the share. 2. Start a sequential read, which queues read-ahead: dd if=<2–3 MB file on the share> of=/dev/null bs=1M & 3. Sleep for 0.01–0.09 seconds, then kill the dd process while I/O is in flight. 4. Open and close another file to leave a deferred close pending: head -c 65536 <another file> >/dev/null 5. Immediately unmount the mount point. 6. Repeat. Results: * 6.8.0-137, 8 workers: panic within about 90 seconds (variant b), with a kdump fingerprint on the BMC. * 6.8.0-137, 4 workers, panic_on_oops=0: oops (b), then (c), within about 5 seconds. * 6.8.0-146, 4 workers for 45 seconds: 5 "Dentry ... still in use" warnings and no fault. * 6.8.0-146, 8 workers: oops (b), then (c), within about 10 seconds. The "still in use" warning occurs several times per minute with 4 workers on 6.8.0-146. The fault requires the deferred work to run after the superblock is freed, so it becomes more likely with parallel workers. == Regression boundary (from the Noble changelog) == * linux 6.8.0-136.136, "Noble update: upstream stable patchset 2026-05-28" (LP: #2154496), added: 340cea84f691c (v7.0) cifs: open files should not hold ref on superblock * linux 6.8.0-139.139, "Noble update: upstream stable patchset 2026-07-09" (LP: #2160250), added: c68337442f03 (v7.1, Cc: stable, Fixes: 340cea84f691c) cifs: Fix busy dentry used after unmounting This commit adds flush_workqueue(deferredclose_wq) in cifs_kill_sb(). It covers variant (a) only. * No Noble 6.8 kernel through 6.8.0-146.146 contains: 75f5c412fa86 (v7.2, Fixes: 340cea84f691c) smb: client: fix busy dentry warning on unmount after DIO This commit adds cifs_sb->outstanding_rreq, waits for in-flight requests, and flushes serverclose_wq and fileinfo_put_wq before kill_anon_super(). This is the mechanism that covers variants (b) and (c). == Request == Track this under CVE-2026-72315, the outstanding-I/O defect fixed by 75f5c412fa86. 1. Apply the attached Noble 6.8 backport of 75f5c412fa86. Noble predates the cifs netfs conversion, so the backport accounts for the cifsFileInfo references held by cifs_readdata, cifs_writedata and cifs_aio_ctx instead of netfs requests. cifs_kill_sb() waits for that per-superblock count to reach zero, then flushes serverclose_wq and fileinfo_put_wq before kill_anon_super(). The patch survived about 76,000 tested cycles. The flush-only alternative still panicked within about 30 seconds with the same cifsiod/cifs_readahead_complete trace. 2. We can validate a candidate kernel within minutes with the attached reproducer. 3. Consider noting in the 6.8.0-136, 6.8.0-137 and 6.8.0-138 release notes that 340cea84f691c shipped without its stable follow-up c68337442f03. Related but separate: 5520e89a5a4f ("smb: client: fix cifsFileInfo reference leak in deferred close", Fixes: c3f207ab29f7) fixes a refcount leak when queue_delayed_work() finds work already pending. It has a different Fixes commit and is not asserted to cause this panic. Please track it separately. == Environment / attachments == Ubuntu 24.04 (Noble), x86_64, HPE ProLiant XL225n Gen10 Plus, in-tree cifs.ko 2.47, and SMB3 to Dell PowerScale. Production mounts and unmounts the share for each cri-o container lifecycle. The lab uses a hand-driven loop. Attached evidence: * Production panic context and kworker trace. * Firmware pstore record from a lab 6.8.0-137 panic. * Live and vmcore dmesg from stock 6.8.0-146. * Vmcore analysis. * Reproducer. * Version, PCI, release and package metadata. * Tested SRU patch. /proc/version_signature reported: Ubuntu 6.8.0-137.137-generic 6.8.12 Ubuntu 6.8.0-146.146-generic 6.8.12 A 3.4 GB kdump vmcore of the 6.8.0-146.146 variant-(b) panic was captured on 2026-09-27 with makedumpfile -c -d 31. It is available on request with the matching vmlinux. Its dmesg and object analysis are attached. To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/linux/+bug/2168697/+subscriptions