-

CVE-2026-90077

net: fix a resource leak in copy_net_ns() error handling path

In the Linux kernel, the following vulnerability has been resolved:

net: fix a resource leak in copy_net_ns() error handling path

Currently, preinit_net() does two things:

  (1) call ns_common_init() which might fail
  (2) initialize resources which does not fail

However, preinit_net() is returning early when (1) fails, and copy_net_ns()
is jumping to the dec_ucounts: label. As a result, resources allocated by
net_alloc() are leaking. We need to call key_remove_domain() and
net_passive_dec() in order to release resources allocated by net_alloc().

We cannot simply jump to the put_userns: label when preinit_net() failed,
for (2) is not yet done. But we can reorder (1) and (2), for there is no
dependency between (1) and (2). Therefore, this patch decouples (1) from
preinit_net() and changes preinit_net() back to a void function, and calls
ns_common_init() after preinit_net() succeeded. Then, we can jump to
immediately after ns_common_free() of the put_userns: label.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 08027f6b790be1e444e4182fb4dc53faa6539d16
Version < 76c847e80d2b6be047707d58e8e05eedbe2593ad
Status affected
Version 08027f6b790be1e444e4182fb4dc53faa6539d16
Version < e69bde4eb566aea8fa97cbb93e0bab608964f1a5
Status affected
Version 08027f6b790be1e444e4182fb4dc53faa6539d16
Version < 3220b62fbb8a55feebd2a826d5ead0f49f09ed5a
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.18
Status affected
Version 0
Version < 6.18
Status unaffected
Version <= 6.18.*
Version 6.18.52
Status unaffected
Version <= 7.2.*
Version 7.2.6
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.2% 0.099
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/76c847e80d2b6be047707d58e8e05eedbe2593ad
https://git.kernel.org/stable/c/e69bde4eb566aea8fa97cbb93e0bab608964f1a5
https://git.kernel.org/stable/c/3220b62fbb8a55feebd2a826d5ead0f49f09ed5a