CVE-2026-89576

Summary

In the Linux kernel, the following vulnerability has been resolved:

dm-era: fix shadowed superblock leak on take-snap failure

metadata_take_snap() bumps the live superblock refcount and then dm_tm_shadow_block() allocates a new block for the metadata snapshot. If the subsequent dm_sm_inc_block() of writeset_tree_root or era_array_root fails, the function only unlocks the clone and returns. The newly allocated shadow block is never returned to the metadata space map, so each failed take-snap permanently leaks one metadata block.

Free the clone with dm_sm_dec_block() on those error paths, matching the final step of metadata_drop_snap().

Affected Software

VendorProductVersion RangeStatus
LinuxLinuxeec40579d84873dfb7021eb24c50360f073237c5 < 54dd21ca945ecc07885012b9f3e8197f091cfba0affected
LinuxLinuxeec40579d84873dfb7021eb24c50360f073237c5 < ef00efb6fcaee88f50891279ceced17c614e97f7affected
LinuxLinuxeec40579d84873dfb7021eb24c50360f073237c5 < e9fa68b89214bc65af0ef963af7ec3cce9f866e0affected
LinuxLinuxeec40579d84873dfb7021eb24c50360f073237c5 < dc731d7fddfd6149f5e88ea080475d18c36d3c64affected
LinuxLinuxeec40579d84873dfb7021eb24c50360f073237c5 < d66ceeefb87ddb097b0546bafc581380b816b048affected
LinuxLinuxeec40579d84873dfb7021eb24c50360f073237c5 < 36ff918637e3517f732188a3c39dbeae5b9cfb1baffected
LinuxLinuxeec40579d84873dfb7021eb24c50360f073237c5 < 6876ca330e741fb8886d12070cb6a7f9cb67257eaffected
LinuxLinuxeec40579d84873dfb7021eb24c50360f073237c5 < 39c5aa3bd8ec3912d2cd0b3fe092642b0d2b0713affected
LinuxLinux3.15affected
LinuxLinux0 < 3.15unaffected
LinuxLinux5.10.270 <= 5.10.*unaffected
LinuxLinux5.15.221 <= 5.15.*unaffected
LinuxLinux6.1.188 <= 6.1.*unaffected
LinuxLinux6.6.157 <= 6.6.*unaffected
LinuxLinux6.12.109 <= 6.12.*unaffected
LinuxLinux6.18.50 <= 6.18.*unaffected
LinuxLinux7.2.4 <= 7.2.*unaffected
LinuxLinux7.3-rc1 <= *unaffected

Weaknesses

References