Re: [PATCH] smb: client: fix cifsFileInfo reference leak in deferred close

From: Paulo Alcantara

Date: Sat Sep 05 2026 - 19:22:30 EST


Fan Wu <fanwu01@xxxxxxxxxx> writes:

> When cifs_close() defers a close, it hands the cifsFileInfo reference
> of the closing struct file to the queued work. Each execution of
> smb2_deferred_work_close() drops one such reference.
>
> deferred_close_scheduled can be false while the work is pending: the
> workqueue clears PENDING when the callback starts to run, before the
> callback clears the flag under deferred_lock. A close in that
> interval requeues the running work, and the callback then clears the
> flag, leaving the requeued work pending with the flag down. A later
> cifs_open() can reuse the handle and its cifs_close() reaches the
> same branch: queue_delayed_work() fails because the work is still
> pending, but cifs_close() returns without dropping the closing file's
> reference. The cifsFileInfo count stays pinned and its tlink, dentry
> and server handle are leaked.
>
> Check the return value and hand off the reference only when work was
> actually queued. Otherwise, use the shared _cifsFileInfo_put(), like
> the mod_delayed_work() branch above: the pending execution already
> owns its reference.
> ...

Applied.