{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-72218","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-08-09T03:40:39.913Z","datePublished":"2026-08-15T05:54:11.672Z","dateUpdated":"2026-08-17T05:10:33.204Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-17T05:10:33.204Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nlockd: Plug nlm_file refcount leak on cached nlm_do_fopen() failure\n\nThe cached-file path in nlm_lookup_file() reaches the found: label\nunconditionally, even when nlm_do_fopen() fails. At that label\n*result and file->f_count are updated before the error is returned.\nThe wrappers nlm3svc_lookup_file() and nlm4svc_lookup_file() then\nbail out of their switch without copying *result back to their\ncaller, so the proc handler's local nlm_file pointer remains NULL\nand the cleanup path skips nlm_release_file(). The f_count\nincrement is never released, and nlm_traverse_files() can no\nlonger reap the file because its refcount never returns to zero\nbetween requests.\n\nShort-circuit the cached path so neither *result nor f_count is\ntouched when nlm_do_fopen() fails on a hashed nlm_file."}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/lockd/svcsubs.c"],"versions":[{"version":"e580323ac0b51ad10ec2e181d1f777479b7983e7","lessThan":"6cd84cefd8b73e85b9eda17b319bd40a670f3a38","status":"affected","versionType":"git"},{"version":"7f024fcd5c97dc70bb9121c80407cf3cf9be7159","lessThan":"fe3b45b56b6c3d4b6b341de27fa291005287a21c","status":"affected","versionType":"git"},{"version":"7f024fcd5c97dc70bb9121c80407cf3cf9be7159","lessThan":"cb3420c047957e565101585bb4f15e1a6e3de6b0","status":"affected","versionType":"git"},{"version":"7f024fcd5c97dc70bb9121c80407cf3cf9be7159","lessThan":"7ce4c23e783e766507b2cef27bbf97e9ca944f1a","status":"affected","versionType":"git"},{"version":"7f024fcd5c97dc70bb9121c80407cf3cf9be7159","lessThan":"84008bf1860e0ef8059a7583a1163f36b704d08a","status":"affected","versionType":"git"},{"version":"7f024fcd5c97dc70bb9121c80407cf3cf9be7159","lessThan":"46d59ff421824b6483549d87f14efffbbbd1f6cb","status":"affected","versionType":"git"},{"version":"7f024fcd5c97dc70bb9121c80407cf3cf9be7159","lessThan":"3a5c55a19cad62f2973be25fe96a1a9e7f618e8a","status":"affected","versionType":"git"},{"version":"7f024fcd5c97dc70bb9121c80407cf3cf9be7159","lessThan":"70a38f87bed7f0694fd07988b47b2db1e10d8df3","status":"affected","versionType":"git"},{"version":"5.10.220","lessThan":"5.10.261","status":"affected","versionType":"semver"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/lockd/svcsubs.c"],"versions":[{"version":"5.15","status":"affected"},{"version":"0","lessThan":"5.15","status":"unaffected","versionType":"semver"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","status":"unaffected","versionType":"semver"},{"version":"7.2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.10.220","versionEndExcluding":"5.10.261"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.15","versionEndExcluding":"5.15.212"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.15","versionEndExcluding":"6.1.178"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.15","versionEndExcluding":"6.6.145"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.15","versionEndExcluding":"6.12.97"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.15","versionEndExcluding":"6.18.40"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.15","versionEndExcluding":"7.1.5"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.15","versionEndExcluding":"7.2"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/6cd84cefd8b73e85b9eda17b319bd40a670f3a38"},{"url":"https://git.kernel.org/stable/c/fe3b45b56b6c3d4b6b341de27fa291005287a21c"},{"url":"https://git.kernel.org/stable/c/cb3420c047957e565101585bb4f15e1a6e3de6b0"},{"url":"https://git.kernel.org/stable/c/7ce4c23e783e766507b2cef27bbf97e9ca944f1a"},{"url":"https://git.kernel.org/stable/c/84008bf1860e0ef8059a7583a1163f36b704d08a"},{"url":"https://git.kernel.org/stable/c/46d59ff421824b6483549d87f14efffbbbd1f6cb"},{"url":"https://git.kernel.org/stable/c/3a5c55a19cad62f2973be25fe96a1a9e7f618e8a"},{"url":"https://git.kernel.org/stable/c/70a38f87bed7f0694fd07988b47b2db1e10d8df3"}],"title":"lockd: Plug nlm_file refcount leak on cached nlm_do_fopen() failure","x_generator":{"engine":"bippy-1.2.0"}}}}