« Volver al listado

CVE-2026-72218

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

lockd: Plug nlm_file refcount leak on cached nlm_do_fopen() failure

The cached-file path in nlm_lookup_file() reaches the found: label unconditionally, even when nlm_do_fopen() fails. At that label *result and file->f_count are updated before the error is returned. The wrappers nlm3svc_lookup_file() and nlm4svc_lookup_file() then bail out of their switch without copying *result back to their caller, so the proc handler's local nlm_file pointer remains NULL and the cleanup path skips nlm_release_file(). The f_count increment is never released, and nlm_traverse_files() can no longer reap the file because its refcount never returns to zero between requests.

Leer descripción completaMostrar menos

Short-circuit the cached path so neither *result nor f_count is touched when nlm_do_fopen() fails on a hashed nlm_file.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-72218",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "e580323ac0b51ad10ec2e181d1f777479b7983e7",
              "lessThan": "6cd84cefd8b73e85b9eda17b319bd40a670f3a38",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "7f024fcd5c97dc70bb9121c80407cf3cf9be7159",
              "lessThan": "fe3b45b56b6c3d4b6b341de27fa291005287a21c",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "7f024fcd5c97dc70bb9121c80407cf3cf9be7159",
              "lessThan": "cb3420c047957e565101585bb4f15e1a6e3de6b0",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "7f024fcd5c97dc70bb9121c80407cf3cf9be7159",
              "lessThan": "7ce4c23e783e766507b2cef27bbf97e9ca944f1a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "7f024fcd5c97dc70bb9121c80407cf3cf9be7159",
              "lessThan": "84008bf1860e0ef8059a7583a1163f36b704d08a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "7f024fcd5c97dc70bb9121c80407cf3cf9be7159",
              "lessThan": "46d59ff421824b6483549d87f14efffbbbd1f6cb",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "7f024fcd5c97dc70bb9121c80407cf3cf9be7159",
              "lessThan": "3a5c55a19cad62f2973be25fe96a1a9e7f618e8a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "7f024fcd5c97dc70bb9121c80407cf3cf9be7159",
              "lessThan": "70a38f87bed7f0694fd07988b47b2db1e10d8df3",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5.10.220",
              "lessThan": "5.10.261",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "fs/lockd/svcsubs.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.15"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "5.15",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.261",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.212",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.178",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.145",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.97",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.40",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.1.5",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "fs/lockd/svcsubs.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-08-15T06:21:40.613",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/3a5c55a19cad62f2973be25fe96a1a9e7f618e8a",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/46d59ff421824b6483549d87f14efffbbbd1f6cb",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/6cd84cefd8b73e85b9eda17b319bd40a670f3a38",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/70a38f87bed7f0694fd07988b47b2db1e10d8df3",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/7ce4c23e783e766507b2cef27bbf97e9ca944f1a",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/84008bf1860e0ef8059a7583a1163f36b704d08a",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/cb3420c047957e565101585bb4f15e1a6e3de6b0",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/fe3b45b56b6c3d4b6b341de27fa291005287a21c",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nlockd: Plug nlm_file refcount leak on cached nlm_do_fopen() failure\n\nThe cached-file path in nlm_lookup_file() reaches the found: label\nunconditionally, even when nlm_do_fopen() fails. At that label\n*result and file->f_count are updated before the error is returned.\nThe wrappers nlm3svc_lookup_file() and nlm4svc_lookup_file() then\nbail out of their switch without copying *result back to their\ncaller, so the proc handler's local nlm_file pointer remains NULL\nand the cleanup path skips nlm_release_file(). The f_count\nincrement is never released, and nlm_traverse_files() can no\nlonger reap the file because its refcount never returns to zero\nbetween requests.\n\nShort-circuit the cached path so neither *result nor f_count is\ntouched when nlm_do_fopen() fails on a hashed nlm_file."
    }
  ],
  "lastModified": "2026-08-17T06:18:22.810",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}