« Volver al listado

CVE-2026-90077

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

net: fix a resource leak in copy_net_ns() error handling path

Currently, preinit_net() does two things:

However, preinit_net() is returning early when (1) fails, and copy_net_ns() is jumping to the dec_ucounts: label. As a result, resources allocated by net_alloc() are leaking. We need to call key_remove_domain() and net_passive_dec() in order to release resources allocated by net_alloc().

We cannot simply jump to the put_userns: label when preinit_net() failed, for (2) is not yet done. But we can reorder (1) and (2), for there is no dependency between (1) and (2).

Leer descripción completaMostrar menos

Therefore, this patch decouples (1) from preinit_net() and changes preinit_net() back to a void function, and calls ns_common_init() after preinit_net() succeeded. Then, we can jump to immediately after ns_common_free() of the put_userns: label.

Detalles técnicos trazas, registros y código del informe original
  (1) call ns_common_init() which might fail
  (2) initialize resources which does not fail

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-90077",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "08027f6b790be1e444e4182fb4dc53faa6539d16",
              "lessThan": "76c847e80d2b6be047707d58e8e05eedbe2593ad",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "08027f6b790be1e444e4182fb4dc53faa6539d16",
              "lessThan": "e69bde4eb566aea8fa97cbb93e0bab608964f1a5",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "08027f6b790be1e444e4182fb4dc53faa6539d16",
              "lessThan": "3220b62fbb8a55feebd2a826d5ead0f49f09ed5a",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "net/core/net_namespace.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.18"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.18",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.18.52",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.6",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "net/core/net_namespace.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-17T17:16:56.930",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/3220b62fbb8a55feebd2a826d5ead0f49f09ed5a",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/76c847e80d2b6be047707d58e8e05eedbe2593ad",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/e69bde4eb566aea8fa97cbb93e0bab608964f1a5",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: fix a resource leak in copy_net_ns() error handling path\n\nCurrently, preinit_net() does two things:\n\n  (1) call ns_common_init() which might fail\n  (2) initialize resources which does not fail\n\nHowever, preinit_net() is returning early when (1) fails, and copy_net_ns()\nis jumping to the dec_ucounts: label. As a result, resources allocated by\nnet_alloc() are leaking. We need to call key_remove_domain() and\nnet_passive_dec() in order to release resources allocated by net_alloc().\n\nWe cannot simply jump to the put_userns: label when preinit_net() failed,\nfor (2) is not yet done. But we can reorder (1) and (2), for there is no\ndependency between (1) and (2). Therefore, this patch decouples (1) from\npreinit_net() and changes preinit_net() back to a void function, and calls\nns_common_init() after preinit_net() succeeded. Then, we can jump to\nimmediately after ns_common_free() of the put_userns: label."
    }
  ],
  "lastModified": "2026-09-17T17:16:56.930",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}