cbcvebase.
CVE-2026-31400
published 2026-04-03

CVE-2026-31400: In the Linux kernel, the following vulnerability has been resolved: sunrpc: fix cache_request leak in cache_release When a reader's file descriptor is closed…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.12%
1.9th percentile
In the Linux kernel, the following vulnerability has been resolved: sunrpc: fix cache_request leak in cache_release When a reader's file descriptor is closed while in the middle of reading a cache_request (rp->offset != 0), cache_release() decrements the request's readers count but never checks whether it should free the request. In cache_read(), when readers drops to 0 and CACHE_PENDING is clear, the cache_request is removed from the queue and freed along with its buffer and cache_head reference. cache_release() lacks this cleanup. The only other path that frees requests with readers == 0 is cache_dequeue(), but it runs only when CACHE_PENDING transitions from set to clear. If that transition already happened while readers was still non-zero, cache_dequeue() will have skipped the request, and no subsequent call will clean it up. Add the same cleanup logic from cache_read() to cache_release(): after decrementing readers, check if it reached 0 with CACHE_PENDING clear, and if so, dequeue and free the cache_request.

Affected

64 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.19.10-1 (forky)linux 6.19.10-1 (forky)
linuxlinux
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 1dfedb293943e491379c9302b428e6f920a73d121dfedb293943e491379c9302b428e6f920a73d12
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < f18c1f2a88ca91357916997cdb0f7adaf14fc497f18c1f2a88ca91357916997cdb0f7adaf14fc497
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 7bcd5e318876ac638c8ceade7a648e76ac8c48e17bcd5e318876ac638c8ceade7a648e76ac8c48e1
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 41f6ba6c98a618043d2cd71030bf9a752dfab8b241f6ba6c98a618043d2cd71030bf9a752dfab8b2
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 301670dcd098c1fe5c2fe90fb3c7a8f4814d2351301670dcd098c1fe5c2fe90fb3c7a8f4814d2351
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < be5c35960e5ead70862736161836e2d1bc7352dcbe5c35960e5ead70862736161836e2d1bc7352dc
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 373457de14281c1fc7cace6fc4c8a267fc176673373457de14281c1fc7cace6fc4c8a267fc176673
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 17ad31b3a43b72aec3a3d83605891e1397d0d06517ad31b3a43b72aec3a3d83605891e1397d0d065
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.19.10-16.19.10-1
linuxlinux_kernel>= 2.6.12.1 < 5.10.2535.10.253
linuxlinux_kernel>= 5.11 < 5.15.2035.15.203
linuxlinux_kernel>= 5.16 < 6.1.1676.1.167
linuxlinux_kernel>= 6.13 < 6.18.206.18.20
linuxlinux_kernel>= 6.19 < 6.19.106.19.10

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
vendor_ubuntu7.1HIGH
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.