SB20260816398 - Resource exhaustion in Linux kernel nfs
Published: August 16, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Resource exhaustion (CVE-ID: CVE-2026-72132)
CWE-ID: CWE-400 - Resource exhaustion
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to incorrect resource accounting in NFS commit-list writeback accounting when handling unstable writes split into multiple sub-folio requests. A local user can trigger writes that are split into many small requests to cause a denial of service.
Exploitation requires NFS client write activity where a folio is split into multiple requests, such as with pNFS flexfiles striping or wsize-limited splitting.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/0ffc032294a29601b1019dba91aa1a930d90df17
- https://git.kernel.org/stable/c/1f646e23372f3444dc5f0bcb5404a49d26756add
- https://git.kernel.org/stable/c/27934d02cbeb8a957dd11c985a579e58d30c5270
- https://git.kernel.org/stable/c/a192b6c149c6ea10cc88869accb78165eb454456
- https://git.kernel.org/stable/c/a442c258320b689f13d2205eaeeddf8b0e630288