« Volver al listado

CVE-2026-72219

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

lockd: Plug nlm_file leak when nlm_do_fopen() fails

A client can repeatedly drive nlm_do_fopen() failures by presenting file handles that the underlying export rejects. After kzalloc_obj() succeeds in nlm_lookup_file(), the freshly allocated nlm_file is not yet inserted into nlm_files[]. The nlm_do_fopen() failure path jumps to out_unlock, which releases nlm_file_mutex and returns without freeing the allocation, so each failure leaks one nlm_file.

Route the failure through out_free so kfree() runs before the function returns.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-72219",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "e580323ac0b51ad10ec2e181d1f777479b7983e7",
              "lessThan": "bca74fff138429f3d5802865f38fc883d53a4f1a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "7f024fcd5c97dc70bb9121c80407cf3cf9be7159",
              "lessThan": "d7c677feb3aa1f42b1026d75a8ea61338b51e4fb",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "7f024fcd5c97dc70bb9121c80407cf3cf9be7159",
              "lessThan": "39f59bf67231ed2eb0cdf6337194360e964b609a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "7f024fcd5c97dc70bb9121c80407cf3cf9be7159",
              "lessThan": "ddfbd816273b4e9c9b836f5b8773664c6f40f807",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "7f024fcd5c97dc70bb9121c80407cf3cf9be7159",
              "lessThan": "1403f1221a35a6caf959bb7bf005741f17263c66",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "7f024fcd5c97dc70bb9121c80407cf3cf9be7159",
              "lessThan": "1161c4b5bd0048c8148e919f818a33cff3623ef0",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "7f024fcd5c97dc70bb9121c80407cf3cf9be7159",
              "lessThan": "3f2dc01b9cb516d4727a3b9263ee58c71ca00ba9",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "7f024fcd5c97dc70bb9121c80407cf3cf9be7159",
              "lessThan": "f16a1513452edb532fec81e591c64c320866719c",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5.10.220",
              "lessThan": "5.10.261",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "fs/lockd/svcsubs.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.15"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "5.15",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.261",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.212",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.178",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.145",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.97",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.40",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.1.5",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "fs/lockd/svcsubs.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-08-15T06:21:40.747",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/1161c4b5bd0048c8148e919f818a33cff3623ef0",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/1403f1221a35a6caf959bb7bf005741f17263c66",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/39f59bf67231ed2eb0cdf6337194360e964b609a",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/3f2dc01b9cb516d4727a3b9263ee58c71ca00ba9",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/bca74fff138429f3d5802865f38fc883d53a4f1a",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/d7c677feb3aa1f42b1026d75a8ea61338b51e4fb",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/ddfbd816273b4e9c9b836f5b8773664c6f40f807",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/f16a1513452edb532fec81e591c64c320866719c",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nlockd: Plug nlm_file leak when nlm_do_fopen() fails\n\nA client can repeatedly drive nlm_do_fopen() failures by presenting\nfile handles that the underlying export rejects. After kzalloc_obj()\nsucceeds in nlm_lookup_file(), the freshly allocated nlm_file is not\nyet inserted into nlm_files[]. The nlm_do_fopen() failure path jumps\nto out_unlock, which releases nlm_file_mutex and returns without\nfreeing the allocation, so each failure leaks one nlm_file.\n\nRoute the failure through out_free so kfree() runs before the\nfunction returns."
    }
  ],
  "lastModified": "2026-08-17T06:18:22.927",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}