CVE-2026-23038

Source
https://cve.org/CVERecord?id=CVE-2026-23038
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-23038.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-23038
Downstream
Related
Published
2026-01-31T11:42:32.599Z
Modified
2026-03-24T09:13:10.619884Z
Summary
pnfs/flexfiles: Fix memory leak in nfs4_ff_alloc_deviceid_node()
Details

In the Linux kernel, the following vulnerability has been resolved:

pnfs/flexfiles: Fix memory leak in nfs4ffallocdeviceidnode()

In nfs4ffallocdeviceidnode(), if the allocation for dsversions fails, the function jumps to the outscratch label without freeing the already allocated dsaddrs list, leading to a memory leak.

Fix this by jumping to the outerrdrain_dsaddrs label, which properly frees the dsaddrs list before cleaning up other resources.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/23xxx/CVE-2026-23038.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
d67ae825a59d639e4d8b82413af84d854617a87e
Fixed
e2dde5dafb80f1af4028ed10ad255f42af71c784
Fixed
27c90d8ed81e7a289c9fe41b5e31d8bb609a3385
Fixed
34b9dd179818ff7af2b36410985fd8166573c62d
Fixed
869862056e100973e76ce9f5f1b01837771b7722
Fixed
86da7efd12295a7e2b4abde5e5984c821edd938f
Fixed
ed5d3f2f6885eb99f729e6ffd946e3aa058bd3eb
Fixed
0c728083654f0066f5e10a1d2b0bd0907af19a58

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-23038.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.0.0
Fixed
5.10.249
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.199
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.162
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.122
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.67
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.7

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-23038.json"