CVE-2026-90077
In the Linux kernel, the following vulnerability has been resolved:
net: fix a resource leak in copy_net_ns() error handling path
Currently, preinit_net() does two things:
However, preinit_net() is returning early when (1) fails, and copy_net_ns() is jumping to the dec_ucounts: label. As a result, resources allocated by net_alloc() are leaking. We need to call key_remove_domain() and net_passive_dec() in order to release resources allocated by net_alloc().
We cannot simply jump to the put_userns: label when preinit_net() failed, for (2) is not yet done. But we can reorder (1) and (2), for there is no dependency between (1) and (2).
Leer descripción completaMostrar menos
Therefore, this patch decouples (1) from preinit_net() and changes preinit_net() back to a void function, and calls ns_common_init() after preinit_net() succeeded. Then, we can jump to immediately after ns_common_free() of the put_userns: label.
Detalles técnicos trazas, registros y código del informe original
(1) call ns_common_init() which might fail (2) initialize resources which does not fail
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.21%
- Percentil entre todas las CVEs puntuadas: 10
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-90077",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "08027f6b790be1e444e4182fb4dc53faa6539d16",
"lessThan": "76c847e80d2b6be047707d58e8e05eedbe2593ad",
"versionType": "git"
},
{
"status": "affected",
"version": "08027f6b790be1e444e4182fb4dc53faa6539d16",
"lessThan": "e69bde4eb566aea8fa97cbb93e0bab608964f1a5",
"versionType": "git"
},
{
"status": "affected",
"version": "08027f6b790be1e444e4182fb4dc53faa6539d16",
"lessThan": "3220b62fbb8a55feebd2a826d5ead0f49f09ed5a",
"versionType": "git"
}
],
"programFiles": [
"net/core/net_namespace.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6.18"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "6.18",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.18.52",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2.6",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"net/core/net_namespace.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-17T17:16:56.930",
"references": [
{
"url": "https://git.kernel.org/stable/c/3220b62fbb8a55feebd2a826d5ead0f49f09ed5a",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/76c847e80d2b6be047707d58e8e05eedbe2593ad",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/e69bde4eb566aea8fa97cbb93e0bab608964f1a5",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: fix a resource leak in copy_net_ns() error handling path\n\nCurrently, preinit_net() does two things:\n\n (1) call ns_common_init() which might fail\n (2) initialize resources which does not fail\n\nHowever, preinit_net() is returning early when (1) fails, and copy_net_ns()\nis jumping to the dec_ucounts: label. As a result, resources allocated by\nnet_alloc() are leaking. We need to call key_remove_domain() and\nnet_passive_dec() in order to release resources allocated by net_alloc().\n\nWe cannot simply jump to the put_userns: label when preinit_net() failed,\nfor (2) is not yet done. But we can reorder (1) and (2), for there is no\ndependency between (1) and (2). Therefore, this patch decouples (1) from\npreinit_net() and changes preinit_net() back to a void function, and calls\nns_common_init() after preinit_net() succeeded. Then, we can jump to\nimmediately after ns_common_free() of the put_userns: label."
}
],
"lastModified": "2026-09-17T17:16:56.930",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}