CVE-2026-72218
CVE CVE-2026-72218EUVD EUVD-2026-58976Published 2026-08-15T05:54:11.000ZLast changed 2026-08-17T05:10:33.000Z
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: lockd: Plug nlm_file refcount leak on cached nlm_do_fopen() failure The cached-file path in nlm_lookup_file() reaches the found: label unconditionally, even when nlm_do_fopen() fails. At that label *result and file->f_count are updated before the error is returned. The wrappers nlm3svc_lookup_file() and nlm4svc_lookup_file() then bail out of their switch without copying *result back to their caller, so the proc handler's local nlm_file pointer remains NULL and the cleanup path skips nlm_release_file(). The f_count increment is never released, and nlm_traverse_files() can no longer reap the file because its refcount never returns to zero between requests. Short-circuit the cached path so neither *result nor f_count is touched when nlm_do_fopen() fails on a hashed nlm_file.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux patch: 7.2; patch: 7.1.5; patch: 6.1.178; 5.10.220 <5.10.261; 7f024fcd5c97dc70bb9121c80407cf3cf9be7159 <70a38f87bed7f0694fd07988b47b2db1e10d8df3; 7f024fcd5c97dc70bb9121c80407cf3cf9be7159 <84008bf1860e0ef8059a7583a1163f36b704d08a; patch: 5.10.261; patch: 6.18.40; 7f024fcd5c97dc70bb9121c80407cf3cf9be7159 <7ce4c23e783e766507b2cef27bbf97e9ca944f1a; patch: 5.15.212; e580323ac0b51ad10ec2e181d1f777479b7983e7 <6cd84cefd8b73e85b9eda17b319bd40a670f3a38; 7f024fcd5c97dc70bb9121c80407cf3cf9be7159 <cb3420c047957e565101585bb4f15e1a6e3de6b0; patch: 6.12.97; patch: 0; patch: 6.6.145; 7f024fcd5c97dc70bb9121c80407cf3cf9be7159 <3a5c55a19cad62f2973be25fe96a1a9e7f618e8a; 7f024fcd5c97dc70bb9121c80407cf3cf9be7159 <fe3b45b56b6c3d4b6b341de27fa291005287a21c; 5.15; 7f024fcd5c97dc70bb9121c80407cf3cf9be7159 <46d59ff421824b6483549d87f14efffbbbd1f6cb
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.