Description
In the Linux kernel, the following vulnerability has been resolved:

net: fix a resource leak in copy_net_ns() error handling path

Currently, preinit_net() does two things:

(1) call ns_common_init() which might fail
(2) initialize resources which does not fail

However, preinit_net() is returning early when (1) fails, and copy_net_ns()
is jumping to the dec_ucounts: label. As a result, resources allocated by
net_alloc() are leaking. We need to call key_remove_domain() and
net_passive_dec() in order to release resources allocated by net_alloc().

We cannot simply jump to the put_userns: label when preinit_net() failed,
for (2) is not yet done. But we can reorder (1) and (2), for there is no
dependency between (1) and (2). Therefore, this patch decouples (1) from
preinit_net() and changes preinit_net() back to a void function, and calls
ns_common_init() after preinit_net() succeeded. Then, we can jump to
immediately after ns_common_free() of the put_userns: label.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service through resource exhaustion
Action: Apply Patch
AI Analysis

Impact

A flaw in the Linux kernel’s copy_net_ns error handling path causes a resource leak when the preinit_net function exits prematurely. Allocated network resources are not freed, allowing repeated triggering to drain kernel memory or network resources. This flaw can degrade system stability or cause crashes, representing a denial‐of‐service vulnerability.

Affected Systems

All Linux kernel versions that contain the original copy_net_ns implementation are affected. No specific version numbers are provided in the advisory, so any kernel build released before this patch is potentially vulnerable.

Risk and Exploitability

The EPSS score is below 1 % and the vulnerability is not listed in CISA’s KEV catalog, indicating a low probability of widespread exploitation. The attack vector is inferred to be local, requiring an attacker to initiate multiple network namespace creations or similar actions that exercise copy_net_ns. The fixed code removes the memory leak and prevents the resource exhaustion that could have been used for a denial‑of‑service attack.

Generated by OpenCVE AI on September 20, 2026 at 03:47 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a kernel update that includes the copy_net_ns leak fix (e.g., install the latest stable kernel released after the patch).
  • Restart networking services or the entire system to ensure no leaked resources remain active after the update.
  • Verify kernel integrity and monitor /proc for anomalous resource usage to confirm the leak is eliminated.

Generated by OpenCVE AI on September 20, 2026 at 03:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 04:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-415

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: net: fix a resource leak in copy_net_ns() error handling path Currently, preinit_net() does two things: (1) call ns_common_init() which might fail (2) initialize resources which does not fail However, preinit_net() is returning early when (1) fails, and copy_net_ns() is jumping to the dec_ucounts: label. As a result, resources allocated by net_alloc() are leaking. We need to call key_remove_domain() and net_passive_dec() in order to release resources allocated by net_alloc(). We cannot simply jump to the put_userns: label when preinit_net() failed, for (2) is not yet done. But we can reorder (1) and (2), for there is no dependency between (1) and (2). Therefore, this patch decouples (1) from preinit_net() and changes preinit_net() back to a void function, and calls ns_common_init() after preinit_net() succeeded. Then, we can jump to immediately after ns_common_free() of the put_userns: label.
Title net: fix a resource leak in copy_net_ns() error handling path
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:05:56.226Z

Reserved: 2026-09-11T19:38:34.785Z

Link: CVE-2026-90077

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:16:56.930

Modified: 2026-09-17T17:16:56.930

Link: CVE-2026-90077

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T04:00:09Z

Weaknesses