Description
In the Linux kernel, the following vulnerability has been resolved:

fat: release buffer head after rebuilding parent

fat_scan_logstart() leaves the matching directory entry's buffer head in
sinfo.bh for the caller to release, just like fat_scan().

fat_rebuild_parent() uses the directory entry to rebuild the parent inode
for the nostale_ro NFS export path, but does not release sinfo.bh after a
successful scan. Release it once fat_build_inode() has consumed the
directory entry data.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Resource Leak leading to possible Denial of Service
Action: Patch Kernel
AI Analysis

Impact

This vulnerability resides in the FAT filesystem implementation of the Linux kernel. It occurs when the function that rebuilds a parent inode for an NFS export path fails to release the buffer head associated with a directory entry after a successful scan. The missing release can result in a memory or resource leak and could allow a malicious client or local user to exhaust kernel memory, potentially destabilizing the system or causing a denial of service. The weakness is a classic resource management flaw.

Affected Systems

All Linux kernel instances that contain the FAT filesystem code and export NFS mounts with the nostale_ro option are potentially affected. The exact kernel versions are not specified in the advisory, but any kernel before the fix referenced in the provided Git commits is vulnerable.

Risk and Exploitability

The EPSS score of less than 1% indicates a very low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The reproduced issue requires interaction with the NFS export mechanism, so the likely attack vector involves a local or possibly remote NFS client that can trigger repeated scans of the directory structure. Given the lack of a direct remote code execution path and the nature of the leak, the potential impact is primarily disruption of kernel memory resources rather than immediate privilege escalation.

Generated by OpenCVE AI on September 19, 2026 at 04:52 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the kernel patch that releases the buffer head after rebuilding the parent inode; update to the latest stable Linux kernel version that includes the fix.
  • If immediate patching is not possible, disable the NFS export with the nostale_ro setting to eliminate the code path that can leak resources.
  • Monitor kernel logs for signs of memory exhaustion or repeated "fat_rebuild_parent" failures and enforce resource limits on NFS services to mitigate potential denial of service.

Generated by OpenCVE AI on September 19, 2026 at 04:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 05:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-772

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: fat: release buffer head after rebuilding parent fat_scan_logstart() leaves the matching directory entry's buffer head in sinfo.bh for the caller to release, just like fat_scan(). fat_rebuild_parent() uses the directory entry to rebuild the parent inode for the nostale_ro NFS export path, but does not release sinfo.bh after a successful scan. Release it once fat_build_inode() has consumed the directory entry data.
Title fat: release buffer head after rebuilding parent
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:08:36.174Z

Reserved: 2026-09-11T19:38:34.801Z

Link: CVE-2026-90318

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:29.683

Modified: 2026-09-17T17:17:29.683

Link: CVE-2026-90318

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T08:30:16Z

Weaknesses
  • CWE-772

    Missing Release of Resource after Effective Lifetime