Missing Release of Resource after Effective Lifetime in Linux kernel - CVE-2026-80898
Published: September 5, 2026
Vulnerability details
The vulnerability allows a local user to retain a folio reference and leave its PG_private_2 state uncleared.
The vulnerability exists due to improper resource cleanup in netfs_pgpriv2_copy_folio() when a copy-to-cache rolling-buffer append fails. A local user can trigger copy-to-cache processing that encounters an append failure to retain a folio reference and leave its PG_private_2 state uncleared.