Missing Release of Resource after Effective Lifetime in Linux kernel - CVE-2026-89576
Published: September 12, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service through metadata block exhaustion.
The vulnerability exists due to improper resource release in metadata_take_snap() when incrementing metadata block references fails after allocating a shadow superblock. A local user can cause snapshot creation to fail after a shadow block is allocated to cause a denial of service through metadata block exhaustion.