-

CVE-2026-90150

pnfs/blocklayout: Fix device leaks on parse failure

In the Linux kernel, the following vulnerability has been resolved:

pnfs/blocklayout: Fix device leaks on parse failure

bl_parse_concat() and bl_parse_stripe() allocate a child device array and
then parse each child in turn.  If parsing a child fails, the failed child is
not counted in nr_children and the parent may be left with a children array
that bl_free_device() will not release when nr_children is zero.

Release the failed child and the already parsed children before returning the
error.  Also make bl_free_device() release the child array whenever the
children pointer is set, so that partially initialised concat or stripe
devices are cleaned up correctly.

bl_parse_scsi() can also fail after assigning d->bdev_file and dropping the
file reference.  Clear the pointer after fput() so that an outer cleanup path
does not put it again.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 5c83746a0cf2831d4b59f5cf99ef5fbf138564e4
Version < 8a2494964edac2a13e82441c2bf887548dc3be0b
Status affected
Version 5c83746a0cf2831d4b59f5cf99ef5fbf138564e4
Version < 1e1c36b206c659cf94c6755a1d821ed1babd32bc
Status affected
Version 5c83746a0cf2831d4b59f5cf99ef5fbf138564e4
Version < 23e4162405c456ce12c772d5882d306135e828ae
Status affected
Version 5c83746a0cf2831d4b59f5cf99ef5fbf138564e4
Version < c056f817e4200fb18079d5052c273a22f191ff0a
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 3.18
Status affected
Version 0
Version < 3.18
Status unaffected
Version <= 6.12.*
Version 6.12.110
Status unaffected
Version <= 6.18.*
Version 6.18.52
Status unaffected
Version <= 7.2.*
Version 7.2.6
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.2% 0.102
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/8a2494964edac2a13e82441c2bf887548dc3be0b
https://git.kernel.org/stable/c/1e1c36b206c659cf94c6755a1d821ed1babd32bc
https://git.kernel.org/stable/c/23e4162405c456ce12c772d5882d306135e828ae
https://git.kernel.org/stable/c/c056f817e4200fb18079d5052c273a22f191ff0a