SB2026040638 - Missing Release of Resource after Effective Lifetime in Linux kernel sunrpc
Published: April 6, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Missing Release of Resource after Effective Lifetime (CVE-ID: CVE-2026-31400)
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper resource management in cache_release when closing a reader file descriptor during a partial read of a cache_request. A local user can close a file descriptor in that state to cause a denial of service.
The issue occurs because the request readers count is decremented without freeing the cache_request when the count reaches zero and CACHE_PENDING is clear, which can result in a memory leak.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/17ad31b3a43b72aec3a3d83605891e1397d0d065
- https://git.kernel.org/stable/c/301670dcd098c1fe5c2fe90fb3c7a8f4814d2351
- https://git.kernel.org/stable/c/373457de14281c1fc7cace6fc4c8a267fc176673
- https://git.kernel.org/stable/c/41f6ba6c98a618043d2cd71030bf9a752dfab8b2
- https://git.kernel.org/stable/c/7bcd5e318876ac638c8ceade7a648e76ac8c48e1
- https://git.kernel.org/stable/c/be5c35960e5ead70862736161836e2d1bc7352dc