cbcvebase.
CVE-2026-23038
published 2026-01-31

CVE-2026-23038: In the Linux kernel, the following vulnerability has been resolved: pnfs/flexfiles: Fix memory leak in nfs4_ff_alloc_deviceid_node() In…

PriorityP418high7.8
EPSS
0.24%
15.9th percentile
In the Linux kernel, the following vulnerability has been resolved: pnfs/flexfiles: Fix memory leak in nfs4_ff_alloc_deviceid_node() In nfs4_ff_alloc_deviceid_node(), if the allocation for ds_versions fails, the function jumps to the out_scratch label without freeing the already allocated dsaddrs list, leading to a memory leak. Fix this by jumping to the out_err_drain_dsaddrs label, which properly frees the dsaddrs list before cleaning up other resources.

Affected

61 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
debianlinux-6.1< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
linuxlinux
linuxlinux>= d67ae825a59d639e4d8b82413af84d854617a87e < e2dde5dafb80f1af4028ed10ad255f42af71c784e2dde5dafb80f1af4028ed10ad255f42af71c784
linuxlinux>= d67ae825a59d639e4d8b82413af84d854617a87e < 27c90d8ed81e7a289c9fe41b5e31d8bb609a338527c90d8ed81e7a289c9fe41b5e31d8bb609a3385
linuxlinux>= d67ae825a59d639e4d8b82413af84d854617a87e < 34b9dd179818ff7af2b36410985fd8166573c62d34b9dd179818ff7af2b36410985fd8166573c62d
linuxlinux>= d67ae825a59d639e4d8b82413af84d854617a87e < 869862056e100973e76ce9f5f1b01837771b7722869862056e100973e76ce9f5f1b01837771b7722
linuxlinux>= d67ae825a59d639e4d8b82413af84d854617a87e < 86da7efd12295a7e2b4abde5e5984c821edd938f86da7efd12295a7e2b4abde5e5984c821edd938f
linuxlinux>= d67ae825a59d639e4d8b82413af84d854617a87e < ed5d3f2f6885eb99f729e6ffd946e3aa058bd3ebed5d3f2f6885eb99f729e6ffd946e3aa058bd3eb
linuxlinux>= d67ae825a59d639e4d8b82413af84d854617a87e < 0c728083654f0066f5e10a1d2b0bd0907af19a580c728083654f0066f5e10a1d2b0bd0907af19a58
linuxlinux_kernel>= 0 < 5.10.249-15.10.249-1
linuxlinux_kernel>= 0 < 6.1.162-16.1.162-1
linuxlinux_kernel>= 0 < 6.12.69-16.12.69-1
linuxlinux_kernel>= 0 < 6.18.8-16.18.8-1
linuxlinux_kernel>= 4.0.0 < 5.10.2495.10.249
linuxlinux_kernel>= 5.11.0 < 5.15.1995.15.199
linuxlinux_kernel>= 5.16.0 < 6.1.1626.1.162
linuxlinux_kernel>= 6.13.0 < 6.18.76.18.7
linuxlinux_kernel>= 6.2.0 < 6.6.1226.6.122
linuxlinux_kernel>= 6.7.0 < 6.12.676.12.67
ubuntulinux
ubuntulinux-aws
ubuntulinux-aws-fips
ubuntulinux-azure
ubuntulinux-azure-5.15

CVSS provenance

vendor_ubuntu7.8HIGH
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.