CVE-2026-52990

Source
https://cve.org/CVERecord?id=CVE-2026-52990
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-52990.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-52990
Downstream
AZL (1)
BELL (1)
DEBIAN (1)
ECHO (1)
OESA (2)
openSUSE (1)
ROOT (4)
SUSE (10)
UBUNTU (1)
Related
Published
2026-06-24T16:29:04Z
Modified
2026-10-08T02:51:04Z
Summary
fsnotify: fix inode reference leak in fsnotify_recalc_mask()
Details

In the Linux kernel, the following vulnerability has been resolved:

fsnotify: fix inode reference leak in fsnotify_recalc_mask()

fsnotify_recalc_mask() fails to handle the return value of __fsnotify_recalc_mask(), which may return an inode pointer that needs to be released via fsnotify_drop_object() when the connector's HAS_IREF flag transitions from set to cleared.

This manifests as a hung task with the following call trace:

INFO: task umount:1234 blocked for more than 120 seconds. Call Trace: __schedule schedule fsnotify_sb_delete generic_shutdown_super kill_anon_super cleanup_mnt task_work_run do_exit do_group_exit

The race window that triggers the iref leak:

Thread A (adding mark) Thread B (removing mark) ────────────────────── ──────────────────────── fsnotify_add_mark_locked(): fsnotify_add_mark_list(): spin_lock(conn->lock) add mark_B(evictable) to list spin_unlock(conn->lock) return

/* ---- gap: no lock held ---- */

                                  fsnotify_detach_mark(mark_A):
                                    spin_lock(mark_A->lock)
                                    clear ATTACHED flag on mark_A
                                    spin_unlock(mark_A->lock)
                                    fsnotify_put_mark(mark_A)

fsnotify_recalc_mask():
  spin_lock(conn->lock)
  __fsnotify_recalc_mask():
    /* mark_A skipped: ATTACHED cleared */
    /* only mark_B(evictable) remains */
    want_iref = false
    has_iref = true  /* not yet cleared */
    -> HAS_IREF transitions true -> false
    -> returns inode pointer
  spin_unlock(conn->lock)
  /* BUG: return value discarded!
   * iput() and fsnotify_put_sb_watched_objects()
   * are never called */

Fix this by deferring the transition true -> false of HAS_IREF flag from fsnotify_recalc_mask() (Thread A) to fsnotify_put_mark() (thread B).

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/52xxx/CVE-2026-52990.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
c3638b5b13740fa31762d414bbce8b7a694e582a
Fixed
8c8afa6444e6bdc145d2bf2f3aeeca6da3e36b42
Fixed
b740cc86816bbc87902ae9db74cd21abde3c8d63
Fixed
5c80289503da3658e3df80280598c68d181eadbd
Fixed
4aca914ac152f5d055ddcb36704d1e539ac08977
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
5.10.220
Fixed
5.11
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
5.15.154
Fixed
5.16
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
ff34ebaa6f6dc1eebce6a8d6f12a1566f33d00fe
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
4f145b67c075324b13d6ae7d5abb6e7a1dbac26d

Affected versions

v5.*
v5.10.220
v5.10.221
v5.10.222
v5.10.223
v5.10.224
v5.10.225
v5.10.226
v5.10.227
v5.10.228
v5.10.229
v5.10.230
v5.10.231
v5.10.232
v5.10.233
v5.10.234
v5.10.235
v5.10.236
v5.10.237
v5.10.238
v5.10.239
v5.10.240
v5.10.241
v5.10.242
v5.10.243
v5.10.244
v5.10.245
v5.10.246
v5.10.247
v5.10.248
v5.10.249
v5.10.250
v5.10.251
v5.10.252
v5.10.253
v5.10.254
v5.10.255
v5.10.256
v5.10.257
v5.10.258
v5.10.259
v5.10.260
v5.10.261
v5.10.262
v5.10.263
v5.10.264
v5.10.265
v5.10.266
v5.10.267
v5.10.268
v5.10.269
v5.10.270
v5.10.271
v5.15.154
v5.15.155
v5.15.156
v5.15.157
v5.15.158
v5.15.159
v5.15.160
v5.15.161
v5.15.162
v5.15.163
v5.15.164
v5.15.165
v5.15.166
v5.15.167
v5.15.168
v5.15.169
v5.15.170
v5.15.171
v5.15.172
v5.15.173
v5.15.174
v5.15.175
v5.15.176
v5.15.177
v5.15.178
v5.15.179
v5.15.180
v5.15.181
v5.15.182
v5.15.183
v5.15.184
v5.15.185
v5.15.186
v5.15.187
v5.15.188
v5.15.189
v5.15.190
v5.15.191
v5.15.192
v5.15.193
v5.15.194
v5.15.195
v5.15.196
v5.15.197
v5.15.198
v5.15.199
v5.15.200
v5.15.201
v5.15.202
v5.15.203
v5.15.204
v5.15.205
v5.15.206
v5.15.207
v5.15.208
v5.15.209
v5.15.210
v5.15.211
v5.15.212
v5.15.213
v5.15.214
v5.15.215
v5.15.216
v5.15.217
v5.15.218
v5.15.219
v5.15.220
v5.15.221
v5.15.222

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-52990.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.19.0
Fixed
6.12.91
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.33
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.0.10

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-52990.json"