Description
In the Linux kernel, the following vulnerability has been resolved:

pnfs/blocklayout: Fix device leaks on parse failure

bl_parse_concat() and bl_parse_stripe() allocate a child device array and
then parse each child in turn. If parsing a child fails, the failed child is
not counted in nr_children and the parent may be left with a children array
that bl_free_device() will not release when nr_children is zero.

Release the failed child and the already parsed children before returning the
error. Also make bl_free_device() release the child array whenever the
children pointer is set, so that partially initialised concat or stripe
devices are cleaned up correctly.

bl_parse_scsi() can also fail after assigning d->bdev_file and dropping the
file reference. Clear the pointer after fput() so that an outer cleanup path
does not put it again.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Resource Leak and Possible Double Free Leading to Denial of Service
Action: Immediate Patch
AI Analysis

Impact

The vulnerability arises when parsing block layout configurations in the Linux kernel. If a child device fails to parse, the failed entry is omitted from the child count but the associated device array is not freed. This results in a memory and resource leak that can gradually exhaust kernel resources, potentially causing system instability or a crash. In addition, the bl_parse_scsi() helper can drop a file reference and later leave the pointer dangling, which may trigger a double release and lead to a kernel panic. The primary impact is a denial of service through resource exhaustion or direct corruption of kernel memory.

Affected Systems

The flaw affects the generic Linux kernel when the pnfs/blocklayout subsystem is active. No specific version list is supplied; any distribution that has not yet incorporated the commit patches is vulnerable.

Risk and Exploitability

The EPSS probability of exploitation is reported as less than 1%, and the vulnerability is not listed in the CISA KEV catalog. The CVSS score is not provided, but the potential for a kernel panic and resource exhaustion signals a high severity if the flaw is triggered. The attack vector is inferred to be through a malformed block layout request or a corrupted Pnfs configuration, likely originating from a privileged user or malicious client. Due to the low perceived exploitation probability, the risk remains moderate, but the consequences warrant prompt remediation.

Generated by OpenCVE AI on September 20, 2026 at 02:18 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the kernel patch that releases partially initialized child device arrays and clears dangling file references as shown in the referenced commits.
  • If a patch is not yet available from your distribution, temporarily disable the pnfs/blocklayout feature or unload the affected module until an updated kernel is installed.
  • Monitor system logs and kernel crash data for signs of memory leaks or panics during block layout processing and consider disabling the feature if instability is observed.

Generated by OpenCVE AI on September 20, 2026 at 02:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: pnfs/blocklayout: Fix device leaks on parse failure bl_parse_concat() and bl_parse_stripe() allocate a child device array and then parse each child in turn. If parsing a child fails, the failed child is not counted in nr_children and the parent may be left with a children array that bl_free_device() will not release when nr_children is zero. Release the failed child and the already parsed children before returning the error. Also make bl_free_device() release the child array whenever the children pointer is set, so that partially initialised concat or stripe devices are cleaned up correctly. bl_parse_scsi() can also fail after assigning d->bdev_file and dropping the file reference. Clear the pointer after fput() so that an outer cleanup path does not put it again.
Title pnfs/blocklayout: Fix device leaks on parse failure
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:06:44.320Z

Reserved: 2026-09-11T19:38:34.789Z

Link: CVE-2026-90150

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:07.943

Modified: 2026-09-17T17:17:07.943

Link: CVE-2026-90150

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T02:30:17Z

Weaknesses

No weakness.