CVE-2026-97606

Unknown

Last modified

CVE-2026-97606 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: fs: autofs: fix memory leak in autofs_fill_super() In autofs_fill_super(), we create a new inode using autofs_new_ino(), however, if we fail to create root_inode, (that is, root_inode failure path), we return -ENOMEM without freeing the new inode(ino) that we created causing a memory leak. Fix this by adding autofs_free_ino() to free the inode we created in root_inode failure path before returning ENOMEM..

Description

In the Linux kernel, the following vulnerability has been resolved: fs: autofs: fix memory leak in autofs_fill_super() In autofs_fill_super(), we create a new inode using autofs_new_ino(), however, if we fail to create root_inode, (that is, root_inode failure path), we return -ENOMEM without freeing the new inode(ino) that we created causing a memory leak. Fix this by adding autofs_free_ino() to free the inode we created in root_inode failure path before returning ENOMEM.

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
LinuxLinux>= 66917f85db6002ed09cd24186258892fcfca64b6, < 4262b91e08e74cb5209ea737c554cf983d332382; >= 66917f85db6002ed09cd24186258892fcfca64b6, < 9933ad1c4ff67680cd59c47f6d2e81b533bcd467; >= 66917f85db6002ed09cd24186258892fcfca64b6, < 6259b5d9bdc45fdb3158406b28c27fa074823159; >= 66917f85db6002ed09cd24186258892fcfca64b6, < 5ab54837fce04a1c9923d0bfd3d5de51fdc768b3
LinuxLinux6.7

References

Timeline

Published
Last Modified
Status
Received

Frequently Asked Questions

What is CVE-2026-97606?
In the Linux kernel, the following vulnerability has been resolved: fs: autofs: fix memory leak in autofs_fill_super() In autofs_fill_super(), we create a new inode using autofs_new_ino(), however, if we fail to create root_inode, (that is, root_inode failure path), we return -ENOMEM without freeing the new inode(ino) that we created causing a memory leak. Fix this by adding autofs_free_ino() to free the inode we created in root_inode failure path before returning ENOMEM.
How severe is CVE-2026-97606?
Severity scoring for CVE-2026-97606 is pending analysis.
How do I fix CVE-2026-97606?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-97606?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST